PT-2019-14077 · Tecno · Tecno Camon

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15348

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys
Description The issue concerns a pre-installed platform app with a package name of com.lovelyfont.defcontainer that contains an exported service named com.lovelyfont.manager.FontCoverService. This service allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user. The attack can be performed by a zero-permission app by writing an attacker-selected message to the logcat log. Executing commands as the system user can allow a third-party app to perform various malicious actions, including video recording the user's screen, factory resetting the device, obtaining the user's notifications, reading the logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages.
Recommendations As a temporary workaround, consider disabling the com.lovelyfont.manager.FontCoverService service until a patch is available. Restrict access to the com.lovelyfont.defcontainer app to minimize the risk of exploitation. Avoid using the device until the issue is resolved, as the app cannot be disabled by the user. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15348

Affected Products

Tecno Camon