First published: Thu Feb 09 2023(Updated: )
The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to filling problems (batch installation of applications).
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei EMUI | =11.0.1 | |
Huawei EMUI | =12.0.0 | |
Huawei EMUI | =12.0.1 | |
Huawei HarmonyOS | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48295 is classified as a high severity vulnerability due to the potential for abuse in application installations.
CVE-2022-48295 affects Huawei EMUI versions 11.0.1, 12.0.0, 12.0.1, and HarmonyOS version 2.0.
To mitigate CVE-2022-48295, users should update their affected Huawei devices to the latest firmware patch recommended by the manufacturer.
Exploitation of CVE-2022-48295 could allow attackers to bypass permission checks and install applications in bulk without proper verification.
As of now, there have been reports indicating that CVE-2022-48295 is under scrutiny for potential exploitation in the wild.