PT-2019-14138 · Google+1 · Android+1

Published

2019-11-14

·

Updated

2020-08-24

·

CVE-2019-15409

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asus ZenFone 5Q Android device with a build fingerprint of asus/WW Phone/ASUS X017D 2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys
Description The issue concerns a pre-installed app with a package name of com.asus.loguploaderproxy that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device that can obtain signatureOrSystem permissions required by other pre-installed apps that exported their capabilities to other pre-installed apps.
Recommendations For the Asus ZenFone 5Q Android device, consider restricting access to the com.asus.loguploaderproxy app to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the app component that allows command execution can help mitigate the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-15409

Affected Products

Android
Asus Zenfone 5Q