PT-2019-14079 · Tecno · Tecno Camon
Published
2019-11-14
·
Updated
2020-08-24
·
CVE-2019-15350
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys
Description
The issue concerns a pre-installed platform app with a package name of
com.lovelyfont.defcontainer that contains an exported service named com.lovelyfont.manager.service.FunctionService. This service allows any app co-located on the device to dynamically load and execute a Dalvik Executable (DEX) file within its own process and with its own system privileges. As a result, a third-party app can perform various malicious actions, including video recording the user's screen, factory resetting the device, obtaining the user's notifications, reading logcat logs, injecting events in the Graphical User Interface (GUI), and obtaining the user's text messages. Additionally, executing code as the system user can allow a third-party app to obtain the user's Wi-Fi passwords, change the default Input Method Editor (IME) with one that contains keylogging functionality, and more.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tecno Camon