CRITICAL🇵🇱 Wersja polska

CVE-2024-42037

CVSS 9.3v3.1pub. 2024-08-08upd. 2024-09-13

Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

🤖 AI Analysis
How it works

The bug results from improper exception handling in the module responsible for graphics (Graphics module). An unhandled exception can be triggered locally without the need for privileges or user interaction. According to the CVSS vector, the vulnerability has a scope extending beyond the attacked component (Scope: Changed), which may indicate the possibility of affecting isolated system components.

Impact

Successful exploitation of the vulnerability may result in a breach of confidentiality of data processed by the device. The high level of integrity and availability indicators in the CVSS vector suggests potentially broader impact on system stability and security.

Mitigation & patch

Apply patches available from the manufacturer according to the references — Huawei security bulletin available at: https://consumer.huawei.com/en/support/bulletin/2024/8/

Who is affected

Devices with Huawei EMUI and Huawei HarmonyOS systems — specific versions indicated in the manufacturer's references (Huawei security bulletin from August 2024).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Huawei Emui

    OS
    Huawei
    12.0.013.0.014.0.0
  • Huawei Harmonyos

    OS
    Huawei
    2.0.02.1.03.0.03.1.04.0.04.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34865CRITICAL10.0PL ✓same product

HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB

CVE-2026-28536CRITICAL9.6PL ✓same product

Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS

CVE-2025-64314CRITICAL9.3PL ✓same product

Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS

CVE-2024-39671CRITICAL9.3PL ✓same product

Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei

CVE-2023-52538CRITICAL9.1PL ✓same product

Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)