CVE-2024-45351
Published: 26 March 2025
Description
Adversaries may exploit software vulnerabilities in client applications to execute code.
Security Summary
CVE-2024-45351 is a code execution vulnerability in the Xiaomi Game Center application. The issue stems from improper input validation (CWE-1284), enabling attackers to execute malicious code. It was published on 2025-03-26 with a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high impact on confidentiality, integrity, and availability.
The vulnerability requires local access (AV:L) with low attack complexity (AC:L) and no privileges (PR:N), but user interaction is necessary (UI:R). An attacker could exploit it by tricking a user into interacting with malicious input via the affected application, leading to arbitrary code execution with high-impact consequences on the local system.
Mitigation details are available in the Xiaomi security advisory at https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=549.
Details
- CWE(s)
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The vulnerability enables arbitrary code execution in a client application (Xiaomi Game Center) via improper input validation requiring user interaction, directly mapping to T1203 Exploitation for Client Execution.