Remote Code Execution Vulnerability in ASUS ZenFone 3 Max by ASUS
CVE-2018-14992
5.5MEDIUM
Summary
The ASUS ZenFone 3 Max features a security flaw due to an exported service within a pre-installed platform app. The vulnerability allows malicious applications to exploit an exposed interface, enabling them to download and install arbitrary apps from the internet without user interaction. This issue occurs via the com.asus.dm.installer.DMInstallerService, where any app on the device can trigger the installation of an unchecked application by providing necessary data, such as download URL and package information. Furthermore, this vulnerability also permits unauthorized uninstallation of apps, posing significant risks to user data integrity and device security.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved