{"api_version":"1","generated_at":"2026-07-23T11:10:28+00:00","cve":"CVE-2019-5245","urls":{"html":"https://cve.report/CVE-2019-5245","api":"https://cve.report/api/cve/CVE-2019-5245.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5245","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5245"},"summary":{"title":"CVE-2019-5245","description":"HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing that could execute arbitrary code.","state":"PUBLIC","assigner":"psirt@huawei.com","published_at":"2019-06-13 16:29:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190612-01-dllhijacking-en","name":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190612-01-dllhijacking-en","refsource":"MISC","tags":["Vendor Advisory"],"title":"Security Advisory - DLL Hijacking Vulnerability on Huawei HiSuite","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5245","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5245","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5245","vulnerable":"1","versionEndIncluding":"9.1.0.300","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"huawei","cpe5":"hisuite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5245","ASSIGNER":"psirt@huawei.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"HiSuite","version":{"version_data":[{"version_value":"Earlier than HiSuite 9.1.0.300 versions"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"DLL hijacking"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190612-01-dllhijacking-en","url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190612-01-dllhijacking-en"}]},"description":{"description_data":[{"lang":"eng","value":"HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing that could execute arbitrary code."}]}},"nvd":{"publishedDate":"2019-06-13 16:29:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:huawei:hisuite:*:*:*:*:*:*:*:*","versionEndIncluding":"9.1.0.300","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5245","Ordinal":"142861","Title":"CVE-2019-5245","CVE":"CVE-2019-5245","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5245","Ordinal":"1","NoteData":"HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this DLL file of the attacker's choosing that could execute arbitrary code.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5245","Ordinal":"2","NoteData":"2019-06-13","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5245","Ordinal":"3","NoteData":"2019-06-13","Type":"Other","Title":"Modified"}]}}}