CVE-2014-8359

Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll in the Mobile Partner directory.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:mobile_partner_firmware:23.009.05.03.1014:*:*:*:*:*:*:*
OR cpe:2.3:h:huawei:ec156:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ec176:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ec177:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () http://osandamalith.wordpress.com/2014/10/20/escalating-local-privileges-using-mobile-partner/ - Exploit () http://osandamalith.wordpress.com/2014/10/20/escalating-local-privileges-using-mobile-partner/ - Exploit
References () http://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html - Exploit () http://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html - Exploit
References () http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-376152.htm - Vendor Advisory () http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-376152.htm - Vendor Advisory
References () http://www.securityfocus.com/bid/70671 - Exploit () http://www.securityfocus.com/bid/70671 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/97682 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/97682 -

Information

Published : 2014-11-13 21:32

Updated : 2024-11-21 02:18


NVD link : CVE-2014-8359

Mitre link : CVE-2014-8359

CVE.ORG link : CVE-2014-8359


JSON object : View

Products Affected

huawei

  • ec176
  • ec177
  • ec156
  • mobile_partner_firmware
CWE
CWE-264

Permissions, Privileges, and Access Controls