PT-2019-14076 · Tecno · Tecno Camon Iclick 2
Publicado
2019-11-14
·
Atualizado
2020-08-24
·
CVE-2019-15347
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys
Description
The pre-installed platform app with a package name of
com.lovelyfont.defcontainer contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user. This is triggered by writing an attacker-selected message to the logcat log. The app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as the system user can allow a third-party app to perform various malicious actions, including video recording the user's screen, factory resetting the device, obtaining the user's notifications, reading the logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tecno Camon Iclick 2