Command Execution Vulnerability in Asus ZenFone 4 Selfie Device by Asus
CVE-2019-15398
7.8HIGH
Summary
The Asus ZenFone 4 Selfie runs a pre-installed application, com.asus.loguploaderproxy, which exposes a critical command execution vulnerability. This app allows other pre-installed applications on the device to execute commands by leveraging system permissions granted to them. This access can be exploited by malicious apps that obtain the same signature or system permissions, enabling unauthorized actions and potentially compromising the integrity and security of user data.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved