Security readout for executives and security teams
Plain-English summary
Certain ASUS Zenfone V Live and ASUS ZenFone 3 Max Android builds shipped with a preinstalled ASUS app that could let another installed app run privileged actions as the Android system user. A malicious app reportedly needs no Android permissions. This is mainly a fleet hygiene and legacy-device risk.
Executive priority
Prioritize identifying and retiring or updating any matching legacy ASUS devices, especially if used for corporate accounts or sensitive workflows. The issue is severe on affected devices, but current evidence does not show broad product impact or active exploitation.
Technical view
CVE-2018-14993 concerns com.asus.splendidcommandagent version 1.2.0.18_160928 exposing SplendidCommandAgentService. The CVE states any co-located app can submit arbitrary commands executed as system user on the specified ASUS build fingerprints, enabling broad device compromise behaviors.
Likely exposure
Exposure appears limited to the exact ASUS Zenfone V Live and ASUS ZenFone 3 Max builds named in the CVE. The bundle does not provide CPEs, CVSS, patch levels, or broader model coverage, so managers should verify against device inventory and vendor firmware records.
Exploitation context
The CVE describes local exploitation by a malicious app already installed on the device, including a zero-permission app. KEV is false in the provided bundle, and no cited source here confirms active exploitation in the wild.
Researcher notes
The evidence is precise about package, service, version, and two build fingerprints, but incomplete on remediation and scoring. Treat claims beyond those devices as unverified unless confirmed by vendor advisories or firmware analysis.
Mitigation direction
- Inventory ASUS Android devices and match model, build fingerprint, and package version.
- Check ASUS or carrier firmware guidance for patched builds or replacement advice.
- Remove affected devices from sensitive use if no supported update exists.
- Restrict sideloading and untrusted app installation on managed Android devices.
- Apply MDM controls to isolate or retire unsupported affected devices.
Validation and detection
- Confirm whether fleet devices match the exact affected build fingerprints.
- Check for com.asus.splendidcommandagent version 1.2.0.18_160928 on suspect devices.
- Review MDM inventory for ASUS Zenfone V Live and ZenFone 3 Max devices.
- Verify firmware update status with ASUS or carrier support records.
- Assess whether affected devices handle corporate credentials, SMS, notifications, or sensitive apps.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-14993 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.kryptowire.com/portal/wp-content/uploads/2018/12/DEFCON-26-Johnson-and-Stavrou-Vulnerable-Out-of-the-Box-An-Eval-of-Android-Carrier-Devices-WP-Updated.pdfCVE reference · x_refsource_MISC
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/CVE reference · x_refsource_MISC
- https://www.kryptowire.com/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
