Vulnerability Description
HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component. An attacker tricks the user install a malicious application, which make the software to reference memory after it has been freed. Successful exploit could cause execution of arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mate 10 Firmware | < alp-al00_8.1.0.311 |
| Huawei | Mate 10 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180711-01-smartphVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180711-01-smartphVendor Advisory
FAQ
What is CVE-2018-7993?
CVE-2018-7993 is a vulnerability with a CVSS score of 7.8 (HIGH). HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component. An attacker tricks the user install a malicious application, whic...
How severe is CVE-2018-7993?
CVE-2018-7993 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7993?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 10 Firmware, Huawei Mate 10.