VYPR
Unrated severityNVD Advisory· Published Nov 14, 2019· Updated Aug 5, 2024

CVE-2019-15410

CVE-2019-15410

Description

Pre-installed app on Asus ZenFone 5Q allows other pre-installed apps to execute arbitrary commands via an exposed component, enabling privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Pre-installed app on Asus ZenFone 5Q allows other pre-installed apps to execute arbitrary commands via an exposed component, enabling privilege escalation.

Vulnerability

A pre-installed app with package name com.asus.loguploaderproxy (versionCode=1570000020, versionName=7.0.0.4_170901) on Asus ZenFone 5Q devices (build fingerprint asus/WW_Phone/ASUS_X017D_2:7.1.1/NGI77B/14.0400.1809.059-20181016:user/release-keys) exposes an accessible component that allows other pre-installed apps to perform command execution. This component is reachable by any pre-installed app on the device that can obtain signatureOrSystem permissions, which are required by other pre-installed apps that export their capabilities [1].

Exploitation

An attacker needs to have a pre-installed app on the device that can acquire signatureOrSystem permissions. Such an app can then invoke the exposed component of com.asus.loguploaderproxy to execute arbitrary commands. No user interaction is required beyond the device running the affected software [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with system privileges, leading to full compromise of the device's confidentiality, integrity, and availability [1].

Mitigation

No patch has been publicly released by Asus as of the publication date. The only mitigation is to remove or disable the pre-installed app if possible, though this may require root access. Users should keep the device updated for any future firmware fixes [1].

References
  1. Home

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asus/ZenFone 5Qdescription
  • Asus/ZenFone 5Qllm-fuzzy
    Range: Android 7.1.1 with build NGI77B / firmware 14.0400.1809.059-20181016

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.