Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8160


The Madapt Driver of some Huawei smart phones with software Earlier than Vicky-AL00AC00B172 versions,Vicky-AL00CC768B122,Vicky-TL00AC01B167,Earlier than Victoria-AL00AC00B172 versions,Victoria-TL00AC00B123,Victoria-TL00AC01B167 has a use after free (UAF) vulnerability. An attacker can trick a user to install a malicious application which has a high privilege to exploit this vulnerability, Successful exploitation may cause arbitrary code execution.


Published

2017-11-22T19:29:03.710

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei vicky-al00a_firmware < vicky-al00ac00b172 Yes
Hardware huawei vicky-al00a - No
Operating System huawei vicky-al00c_firmware vicky-al00cc768b122 Yes
Hardware huawei vicky-al00c - No
Operating System huawei vicky-tl00a_firmware vicky-tl00ac01b167 Yes
Hardware huawei vicky-tl00a - No
Operating System huawei victoria-al00a_firmware < victoria-al00ac00b172_ Yes
Hardware huawei victoria-al00a - No
Operating System huawei victoria-tl00a_firmware victoria-tl00ac00b123 Yes
Hardware huawei victoria-tl00a - No
Operating System huawei victoria-tl00a_firmware victoria-tl00ac01b167 Yes
Hardware huawei victoria-tl00a - No

References