Latest YouTube Video

Monday, May 4, 2015

[FD] HUAWEI MobiConnect 23.9.17.216 - Privilege Escalation Vulnerability

Document Title: =============== HUAWEI MobiConnect 23.9.17.216 - Privilege Escalation Vulnerability References (Source): ==================== http://ift.tt/1EKAbbc Release Date: ============= 2015-05-04 Vulnerability Laboratory ID (VL-ID): ==================================== 1389 Common Vulnerability Scoring System: ==================================== 6.7 Product & Service Introduction: =============================== Wherever you are, our offer Mobiconnect allows you to work with the same comfort that company for your laptop. You can, in complete freedom ... Surfing the Internet, Consult your mail and all your attachments, Access your documents and business applications. In addition to GPRS / EDGE unlimited, you can send free SMS to the Mobilis network on your computer. (Copy of the Vendor Homepage: http://ift.tt/1DOyGFc ) Abstract Advisory Information: ============================== An independent vulnerability researcher discovered a local privilege escalation vulnerability in the official HUAWEI MobiConnect 23.009.17.00.216 software. Vulnerability Disclosure Timeline: ================================== 2014-00-00: Researcher Notification & Coordination (Hadji Samir) 2014-12-23: Vendor Notification (PSIRT Team) 2014-12-26: Vendor Response/Feedback (PSIRT Team) 2014-04-17: Vendor Fix/Patch (HUAWEI Developer Team) 2014-05-04: Public Disclosure (Vulnerability Laboratory) Discovery Status: ================= Published Affected Product(s): ==================== HUAWEI Product: MobiConnect HUAWEI 23.009.17.00.216 Exploitation Technique: ======================= Local Severity Level: =============== High Technical Details & Description: ================================ A local privilege escalation vulnerability has been discovered in the official HUAWEI MobiConnect 23.009.17.00.216 software. The local security vulnerability allows an attackers to gain higher access privileges by execution of arbitrary codes in connection with dll hijacking. The security risk of the local privilege escalation vulnerability is estimated as high with a cvss (common vulnerability scoring system) count of 6.7. Exploitation of the vulnerability requires a local privileged systen user account without user for interaction. Successful exploitation of the privilege escalation web vulnerability results in software- or system compromise. Proof of Concept (PoC): ======================= The local vulnerability can be exploited by local attackers with restricted system privileges and without user interaction. For security demonstration or to reproduce the security vulnerability follow the provided information and steps below to continue.

Source: Gmail -> IFTTT-> Blogger

No comments: