PT-2019-14124 · Google+1 · Android+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15395

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN X00G/ASUS X00G 1:7.0/NRD90M/IN X00G-14.02.1807.33-20180706:user/release-keys
Description The issue concerns a pre-installed app with a package name of com.asus.loguploaderproxy that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device that can obtain signatureOrSystem permissions required by other pre-installed apps that exported their capabilities to other pre-installed apps.
Recommendations For the Asus ZenFone 3s Max Android device, consider restricting access to the com.asus.loguploaderproxy app to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the app component that allows command execution can help mitigate the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15395

Affected Products

Android
Asus Zenfone 3 Max