{"api_version":"1","generated_at":"2026-07-23T01:51:52+00:00","cve":"CVE-2016-8769","urls":{"html":"https://cve.report/CVE-2016-8769","api":"https://cve.report/api/cve/CVE-2016-8769.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8769","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8769"},"summary":{"title":"CVE-2016-8769","description":"Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.","state":"PUBLISHED","assigner":"huawei","published_at":"2017-04-02 20:59:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-264","unquoted service path"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"6.7","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/40807/","name":"https://www.exploit-db.com/exploits/40807/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Huawei UTPS - Unquoted Service Path Privilege Escalation - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94403","name":"http://www.securityfocus.com/bid/94403","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Huawei UTPS CVE-2016-8769 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en","name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory - Unquoted Service Path Vulnerability in Huawei UTPS Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/","name":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","URL Repurposed"],"title":"0day discovery System level access by Privilege Escalation of  Huawei manufactured Airtel & Photon Dongles – Security-Geek","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8769","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8769","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Huawei Technologies Co., Ltd.","product":"Huawei UTPS","version":"affected earlier than UTPS-V200R003B015D16SPC00C983","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8769","vulnerable":"1","versionEndIncluding":"v200r003b015d15sp00c983","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"utps_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:35:01.051Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/"},{"name":"94403","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94403"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en"},{"name":"40807","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/40807/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Huawei UTPS","vendor":"Huawei Technologies Co., Ltd.","versions":[{"status":"affected","version":"earlier than UTPS-V200R003B015D16SPC00C983"}]}],"datePublic":"2017-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed."}],"problemTypes":[{"descriptions":[{"description":"unquoted service path","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-02T09:57:01.000Z","orgId":"25ac1063-e409-4190-8079-24548c77ea2e","shortName":"huawei"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/"},{"name":"94403","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94403"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en"},{"name":"40807","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/40807/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@huawei.com","DATE_PUBLIC":"2017-11-15T00:00:00","ID":"CVE-2016-8769","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Huawei UTPS","version":{"version_data":[{"version_value":"earlier than UTPS-V200R003B015D16SPC00C983"}]}}]},"vendor_name":"Huawei Technologies Co., Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"unquoted service path"}]}]},"references":{"reference_data":[{"name":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/","refsource":"MISC","url":"http://www.security-geek.in/2017/02/07/0day-discovery-system-level-access-by-privilege-escalation-of-huawei-manufactured-airtel-photon-dongles/"},{"name":"94403","refsource":"BID","url":"http://www.securityfocus.com/bid/94403"},{"name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en","refsource":"CONFIRM","url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161116-01-utps-en"},{"name":"40807","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/40807/"}]}}}},"cveMetadata":{"assignerOrgId":"25ac1063-e409-4190-8079-24548c77ea2e","assignerShortName":"huawei","cveId":"CVE-2016-8769","datePublished":"2017-04-02T20:00:00.000Z","dateReserved":"2016-10-18T00:00:00.000Z","dateUpdated":"2024-09-16T22:21:07.830Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-02 20:59:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-264","unquoted service path"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:utps_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"v200r003b015d15sp00c983","matchCriteriaId":"8F8526F6-4933-4165-A487-C0A528EB1C5C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8769","Ordinal":"1","Title":"CVE-2016-8769","CVE":"CVE-2016-8769","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8769","Ordinal":"1","NoteData":"Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.","Type":"Description","Title":"CVE-2016-8769"},{"CveYear":"2016","CveId":"8769","Ordinal":"2","NoteData":"2017-04-02","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8769","Ordinal":"3","NoteData":"2017-09-02","Type":"Other","Title":"Modified"}]}}}