CVE-2025-46014

Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:honor:pc_manager:*:*:*:*:*:*:*:*

History

15 Oct 2025, 20:06

Type Values Removed Values Added
First Time Honor
Honor pc Manager
References () https://github.com/Souhardya/Exploit-PoCs/tree/main/HonorPCManager-PrivEsc - () https://github.com/Souhardya/Exploit-PoCs/tree/main/HonorPCManager-PrivEsc - Third Party Advisory, Exploit
CPE cpe:2.3:a:honor:pc_manager:*:*:*:*:*:*:*:*

30 Jun 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-276
CWE-284
Summary
  • (es) Se descubrió que varios servicios en Honor Device Co., Ltd Honor PC Manager v16.0.0.118 conectaban servicios a la tubería con nombre iMateBookAssistant con atributos de seguridad predeterminados o demasiado permisivos, lo que provocaba una escalada de privilegios.

30 Jun 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-30 02:15

Updated : 2025-10-15 20:06


NVD link : CVE-2025-46014

Mitre link : CVE-2025-46014

CVE.ORG link : CVE-2025-46014


JSON object : View

Products Affected

honor

  • pc_manager
CWE
CWE-276

Incorrect Default Permissions

CWE-284

Improper Access Control