PT-2019-14074 · Tecno · Tecno Camon Iclick
Publicado
2019-11-14
·
Atualizado
2020-08-24
·
CVE-2019-15345
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys
Description
The pre-installed platform app
com.lovelyfont.defcontainer contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to dynamically load and execute a Dalvik Executable (DEX) file within its own process and with its own system privileges. This can be exploited by a zero-permission app to execute commands as the system user, potentially allowing actions such as video recording the user's screen, factory resetting the device, obtaining the user's notifications, reading logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages.Recommendations
As a temporary workaround, consider disabling the
com.lovelyfont.manager.service.FunctionService service until a patch is available. Restrict access to the com.lovelyfont.defcontainer app to minimize the risk of exploitation. Avoid using the com.lovelyfont.defcontainer app until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exposure of Resource to Wrong Sphere
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tecno Camon Iclick