Command Execution Vulnerability in Asus ZenFone 3s Max by Asus
CVE-2019-15403
7.8HIGH
Summary
The Asus ZenFone 3s Max contains a security flaw that enables pre-installed applications to execute commands without proper authorization. This flaw arises from a specific app, identified by the package name com.asus.loguploaderproxy, which possesses capabilities that allow other pre-installed applications to access its functionalities. Any app on the device that has been granted signature or system permissions can exploit this vulnerability, posing a significant security risk to users by potentially allowing malicious actions to be carried out without user consent.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved