Description
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.
Problem types
CWE-427 Uncontrolled Search Path Element
Product status
ZXCLOUD-iRAI-ClientV7.2X
Credits
Runzi Zhao, Feng Ye and Ziwei Wang
References
support.zte.com.cn/...ui/bulletin/detail/8107253322107965601