Race condition in Huawei products - CVE-2019-5228
Published: November 15, 2019
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists in certain detection module due to a race condition when the system does not lock certain function properly. A local user can trick a victim to install a malicious application, trigger out of bound write and execute arbitrary code on the system.
Affected software
P30 Pro
Honor V20
How to mitigate CVE-2019-5228
P30 Pro - update to 9.1.0.193
Honor V20 - update to 9.1.0.233