CRITICAL🇵🇱 Wersja polska

CVE-2025-64314

CVSS 9.3v3.1pub. 2025-11-28upd. 2025-12-02

Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

🤖 AI Analysis
How it works

The vulnerability consists of improper permission control in the memory management module, classified as type confusion (CWE-843). The attack vector indicates local access without privilege requirements and without user interaction, however with potential impact exceeding the scope of the attacked component (Scope: Changed). An attacker operating locally can manipulate object types in memory in a manner exceeding their assigned privileges.

Impact

Successful exploitation of the vulnerability may result in data confidentiality breach — the vendor indicates impact on confidentiality. The CVSS vector also indicates high impact on integrity and availability, suggesting the possibility of unauthorized data access, resource modification, or system destabilization.

Mitigation & patch

Security patches available from the vendor should be applied according to references — security bulletin available at: https://consumer.huawei.com/cn/support/bulletinlaptops/2025/11/

Who is affected

Huawei HarmonyOS — specific versions indicated in vendor references (Huawei security bulletin from November 2025)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Huawei Harmonyos

    OS
    Huawei
    5.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34865CRITICAL10.0PL ✓same product

HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB

CVE-2026-28536CRITICAL9.6PL ✓same product

Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS

CVE-2024-42037CRITICAL9.3PL ✓same product

Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS

CVE-2024-39671CRITICAL9.3PL ✓same product

Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei

CVE-2023-52538CRITICAL9.1PL ✓same product

Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)