Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
The vulnerability results from improper assignment of default permissions in the window management module. A remote, unauthenticated attacker can exploit this vulnerability over the network without any user interaction. The result is a compromise of system integrity and availability.
An attacker can compromise system integrity and cause loss of device availability, potentially leading to system instability or denial of service.
Apply patches available from the manufacturer according to references — Huawei Security Bulletin from April 2024 available at https://consumer.huawei.com/en/support/bulletin/2024/4/
Huawei devices running EMUI and HarmonyOS — versions specified in the manufacturer's references (Huawei Security Bulletin from April 2024)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HHuawei Emui
OSHuawei12.0.013.0.0Huawei Harmonyos
OSHuawei2.0.02.1.03.0.03.1.04.0.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS
Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei