Cyber Posture

CVE-2024-45351

High

Published: 26 March 2025

Published
26 March 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0007 20.6th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities in client applications to execute code.

Security Summary

CVE-2024-45351 is a code execution vulnerability in the Xiaomi Game Center application. The issue stems from improper input validation (CWE-1284), enabling attackers to execute malicious code. It was published on 2025-03-26 with a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high impact on confidentiality, integrity, and availability.

The vulnerability requires local access (AV:L) with low attack complexity (AC:L) and no privileges (PR:N), but user interaction is necessary (UI:R). An attacker could exploit it by tricking a user into interacting with malicious input via the affected application, leading to arbitrary code execution with high-impact consequences on the local system.

Mitigation details are available in the Xiaomi security advisory at https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=549.

Details

CWE(s)
CWE-1284

MITRE ATT&CK Enterprise Techniques

T1203 Exploitation for Client Execution Execution
Adversaries may exploit software vulnerabilities in client applications to execute code.
Why these techniques?

The vulnerability enables arbitrary code execution in a client application (Xiaomi Game Center) via improper input validation requiring user interaction, directly mapping to T1203 Exploitation for Client Execution.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References