PT-2019-14073 · Tecno · Tecno Camon Iclick
Published
2019-11-14
·
Updated
2020-08-24
·
CVE-2019-15344
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys
Description
The pre-installed platform app
com.lovelyfont.defcontainer contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This can be exploited by a zero-permission app. Additionally, the accompanying app com.ekesoo.lovelyhifonts makes network requests using HTTP, making it vulnerable to Man-in-the-Middle (MITM) attacks, which can inject commands in network responses to be executed as the system user. This can allow a third-party app to perform various malicious actions, including video recording the user's screen, factory resetting the device, obtaining user notifications, reading logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tecno Camon Iclick