Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Huawei HiSuite 安全漏洞
Vulnerability Description
Huawei HiSuite 4.0.4.204_ove (Out of China)之前的版本和4.0.4.301 (China)之前的版本中存在提权漏洞,该漏洞源于程序对HiSuite服务目录使用弱的ACL (FILE_WRITE_DATA for BUILTIN\Users)。本地攻击者可通过载入恶意的DLL文件利用该漏洞获取SYSTEM权限。
CVSS Information
N/A
Vulnerability Type
N/A