CVE-2017-2699: Malicious File Upload
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2699?
CVE-2017-2699 is a vulnerability in the Huawei Themes APP that allows attackers to upload theme packs containing malicious files.
What is the severity of CVE-2017-2699?
The severity of CVE-2017-2699 is high, with a severity value of 7.8.
Which software versions are affected by CVE-2017-2699?
Versions earlier than PLK-UL00C17B385, CRR-L09C432B380, and LYO-L21C577B128 of the Huawei Themes APP are affected by CVE-2017-2699.
How can an attacker exploit CVE-2017-2699?
An attacker can exploit CVE-2017-2699 by uploading theme packs with malicious files and tricking users into installing them.
Where can I find more information about CVE-2017-2699?
You can find more information about CVE-2017-2699 at the following references: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170222-01-theme-en and http://www.securityfocus.com/bid/96424.