CVE-2014-2271 Information
Description
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1 as used in Huawei P2 devices before V100R001C00B043 falls back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-401529.htm http://www.securityfocus.com/bid/71381 https://exchange.xforce.ibmcloud.com/vulnerabilities/99089 https://labs.f-secure.com/advisories/kingsoft-office-remote-code-execution/ https://labs.f-secure.com/assets/763/original/mwri_advisory_huawei_kingsoft-office.pdf
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: