PT-2019-14132 · Google+1 · Android+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15403

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asus ZenFone 3s Max Android device with a build fingerprint of asus/IN X00G/ASUS X00G 1:7.0/NRD90M/IN X00G-14.02.1807.33-20180706:user/release-keys
Description The issue concerns a pre-installed app with a package name of com.asus.loguploaderproxy that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device that can obtain signatureOrSystem permissions required by other pre-installed apps that exported their capabilities to other pre-installed apps.
Recommendations For the Asus ZenFone 3s Max Android device, consider restricting access to the com.asus.loguploaderproxy app to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and restrict permissions of pre-installed apps to prevent them from obtaining signatureOrSystem permissions that could be used to access the vulnerable app component.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15403

Affected Products

Android
Asus Zenfone 3 Max