cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-401529.htm | third party advisory |
http://www.securityfocus.com/bid/71381 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99089 | vdb entry third party advisory |
https://labs.f-secure.com/advisories/kingsoft-office-remote-code-execution/ | third party advisory |
https://labs.f-secure.com/assets/763/original/mwri_advisory_huawei_kingsoft-office.pdf | third party advisory |