First published: Tue Jul 31 2018(Updated: )
HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component. An attacker tricks the user install a malicious application, which make the software to reference memory after it has been freed. Successful exploit could cause execution of arbitrary code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 10 Firmware | <alp-al00_8.1.0.311 | |
Huawei Mate 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7993 is critical with a CVSS score of 7.8.
HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 are affected by CVE-2018-7993.
CVE-2018-7993 is a use after free vulnerability in the mediaserver component of HUAWEI Mate 10 smartphones.
An attacker can exploit CVE-2018-7993 by tricking the user into installing a malicious application that causes the software to reference memory after it has been freed.
To fix CVE-2018-7993, users of HUAWEI Mate 10 smartphones should update to version ALP-AL00 8.1.0.311 or later.