Command Execution Vulnerability in Asus ZenFone 3s Max by Asus
CVE-2019-15403

7.8HIGH

Key Information:

Vendor
Asus
Vendor
CVE Published:
14 November 2019

Summary

The Asus ZenFone 3s Max contains a security flaw that enables pre-installed applications to execute commands without proper authorization. This flaw arises from a specific app, identified by the package name com.asus.loguploaderproxy, which possesses capabilities that allow other pre-installed applications to access its functionalities. Any app on the device that has been granted signature or system permissions can exploit this vulnerability, posing a significant security risk to users by potentially allowing malicious actions to be carried out without user consent.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.