CVE-2024-56436
Published: 08 January 2025
Description
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Security Summary
CVE-2024-56436 is a cross-process screen stack vulnerability in the UIExtension module. It carries a CVSS v3.1 base score of 5.5 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) and is linked to CWE-1021 (as well as NVD-CWE-noinfo). Successful exploitation may affect service confidentiality.
A local attacker with no privileges required can exploit this vulnerability through low-complexity attacks that necessitate user interaction. Upon success, the attacker achieves high confidentiality impact, enabling unauthorized access to sensitive data across processes without affecting integrity or availability.
Huawei has published a security bulletin with further details at https://consumer.huawei.com/en/support/bulletin/2025/1/.
Details
- CWE(s)