The Huawei Mobile Broadband HL Service and earlier uses a weak ACL for the MobileBrServ program data directory, which allows local users to gain SYSTEM privileges by modifying VERSION.dll.

Source: CVE-2016-2855

