First published: Thu Apr 25 2019(Updated: )
The ASUS Zenfone V Live Android device with a build fingerprint of asus/VZW_ASUS_A009/ASUS_A009:7.1.1/NMF26F/14.0610.1802.78-20180313:user/release-keys and the Asus ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys both contain a pre-installed platform app with a package name of com.asus.splendidcommandagent (versionCode=1510200090, versionName=1.2.0.18_160928) that contains an exported service named com.asus.splendidcommandagent.SplendidCommandAgentService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, obtain the user's text messages, and more.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Zenfone V Live Firmware | ||
ASUS Zenfone V Live | ||
Asus Zenfone 3 Max Firmware | ||
Asus ZenFone 3 Max |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14993 is considered to have high severity due to the potential for unauthorized access and exploitation of the affected devices.
CVE-2018-14993 affects the security of the Asus Zenfone V Live and Asus ZenFone 3 Max by exposing them to vulnerabilities that could lead to data breaches.
To fix CVE-2018-14993, users should update their device firmware to the latest version provided by ASUS that addresses this vulnerability.
CVE-2018-14993 impacts the ASUS Zenfone V Live and Asus ZenFone 3 Max running specific firmware versions.
CVE-2018-14993 is considered widespread due to the prevalence of the affected ASUS Android devices in use.