CVE-2016-5821

Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:huawei:hisuite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/137733/Huawei-HiSuite-For-Windows-4.0.3.301-Privilege-Escalation.html - Exploit () http://packetstormsecurity.com/files/137733/Huawei-HiSuite-For-Windows-4.0.3.301-Privilege-Escalation.html - Exploit
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160624-01-hisuite-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160624-01-hisuite-en - Vendor Advisory
References () http://www.securityfocus.com/archive/1/538797/100/0/threaded - () http://www.securityfocus.com/archive/1/538797/100/0/threaded -
References () http://www.securityfocus.com/bid/91418 - () http://www.securityfocus.com/bid/91418 -
References () https://labs.bluefrostsecurity.de/advisories/bfs-sa-2016-003/ - () https://labs.bluefrostsecurity.de/advisories/bfs-sa-2016-003/ -

Information

Published : 2016-07-13 15:59

Updated : 2024-11-21 02:55


NVD link : CVE-2016-5821

Mitre link : CVE-2016-5821

CVE.ORG link : CVE-2016-5821


JSON object : View

Products Affected

huawei

  • hisuite
CWE
CWE-264

Permissions, Privileges, and Access Controls