CVE-2017-2699
Last modified
CVE-2017-2699 is a vulnerability of currently unknown severity. The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a privilege elevation vulnerability. An attacker could exploit this vulnerability to upload theme packs containing malicious files and trick users into installing the theme packets, resulting in the execution of arbitrary code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 7 Firmware | < plk-ul00c17b385 |
| Huawei | Mate S Firmware | < crr-l09c432b380 |
| Huawei | Lyo-L21 Firmware | < lyo-l21c577b128 |
References
- http://www.securityfocus.com/bid/96424Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/96424Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2699?
How severe is CVE-2017-2699?
How do I fix CVE-2017-2699?
Are you affected by CVE-2017-2699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
