First published: Wed Nov 22 2017(Updated: )
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a arbitrary memory write vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter to the driver of the smart phone, causing privilege escalation.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mtk Platform Smart Phone Firmware | <nice-al00c00b155 | |
Huawei Mtk Platform Smart Phone |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8181 is considered a high severity vulnerability due to its potential for arbitrary memory write operations.
To fix CVE-2017-8181, users should update their Huawei smart phones to at least the Nice-AL00C00B155 version to mitigate the vulnerability.
CVE-2017-8181 affects Huawei smart phones that run on the MTK platform with firmware versions prior to Nice-AL00C00B155.
CVE-2017-8181 is an arbitrary memory write vulnerability caused by insufficient input verification in the camera driver.
Yes, exploitation of CVE-2017-8181 can allow an attacker to gain special privileges and compromise the affected Huawei smart phone.