CVE-2016-5821
Huawei HiSuite For Windows 4.0.3.301 Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
Huawei HiSuite en versiones anteriores a 4.0.4.204_ove (fuera de China) y en versiones anteriores a 4.0.4.301 (China) utiliza un ACL débil (FILE_WRITE_DATA para BUILTIN\Users) para el directorio de servicio HiSuite, lo que permite a usuarios locales obtener privilegios SYSTEM a través de un archivo Troyano (1) SspiCli.dll o (2) USERENV.dll o posiblemente otros archivos DLL no especificados.
A privilege escalation vulnerability was identified in the Huawei HiSuite software which can be used by a local user to elevate privileges to become the SYSTEM user. The root cause of the problem are insecure ACLs on the HandSet service directory which allows any authenticated user to place a crafted DLL file in that directory to perform a DLL hijacking attack. Versions 4.0.3.301 and below are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-23 CVE Reserved
- 2016-06-30 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/538797/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/91418 | Vdb Entry | |
https://labs.bluefrostsecurity.de/advisories/bfs-sa-2016-003 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/137733/Huawei-HiSuite-For-Windows-4.0.3.301-Privilege-Escalation.html | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160624-01-hisuite-en | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Hisuite Search vendor "Huawei" for product "Hisuite" | <= 4.0.3.301 Search vendor "Huawei" for product "Hisuite" and version " <= 4.0.3.301" | - |
Affected
|