PT-2019-14117 · Coolpad+1 · Coolpad 1851+1

Publicado

2019-11-14

·

Atualizado

2020-08-24

·

CVE-2019-15388

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys
Description The issue concerns a pre-installed platform app with a package name of com.lovelyfont.defcontainer that contains an exported service named com.lovelyfont.manager.FontCoverService. This service allows any app co-located on the device to supply arbitrary commands to be executed as the system user. The app cannot be disabled by the user, and the attack can be performed by a zero-permission app. Additionally, the accompanying app com.ekesoo.lovelyhifonts makes network requests using HTTP, making it vulnerable to Man-in-the-Middle (MITM) attacks. An attacker can inject a command in a network response that will be executed as the system user, potentially allowing a third-party app to perform various malicious actions, such as video recording the user's screen, factory resetting the device, obtaining the user's notifications, reading the logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15388

Produtos afetados

Android
Coolpad 1851