First published: Wed Nov 15 2017(Updated: )
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 7 Firmware | <plk-ul00c17b385 | |
Huawei Honor 7 | ||
Huawei Mate S Firmware | <crr-l09c432b380 | |
Huawei Mate S | ||
Huawei Lyo-l21 Firmware | <lyo-l21c577b128 | |
Huawei Lyo-l21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2699 is a vulnerability in the Huawei Themes APP that allows attackers to upload theme packs containing malicious files.
The severity of CVE-2017-2699 is high, with a severity value of 7.8.
Versions earlier than PLK-UL00C17B385, CRR-L09C432B380, and LYO-L21C577B128 of the Huawei Themes APP are affected by CVE-2017-2699.
An attacker can exploit CVE-2017-2699 by uploading theme packs with malicious files and tricking users into installing them.
You can find more information about CVE-2017-2699 at the following references: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170222-01-theme-en and http://www.securityfocus.com/bid/96424.