LiveActive security incident?Get immediate response
CVE Record

CVE-2018-14993: The ASUS Zenfone V Live Android device with a build fingerprint of asus/VZW_ASUS_A009/ASUS_A009:7.1.1/NMF26...

The ASUS Zenfone V Live Android device with a build fingerprint of asus/VZW_ASUS_A009/ASUS_A009:7.1.1/NMF26F/14.0610.1802.78-20180313:user/release-keys and the Asus ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys both contain a pre-installed platform app with a package name of com.asus.splendidcommandagent (versionCode=1510200090, versionName=1.2.0.18_160928) that contains an exported service named com.asus.splendidcommandagent.SplendidCommandAgentService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. Executing commands as system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, obtain the user's text messages, and more.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Certain ASUS Zenfone V Live and ASUS ZenFone 3 Max Android builds shipped with a preinstalled ASUS app that could let another installed app run privileged actions as the Android system user. A malicious app reportedly needs no Android permissions. This is mainly a fleet hygiene and legacy-device risk.

Executive priority

Prioritize identifying and retiring or updating any matching legacy ASUS devices, especially if used for corporate accounts or sensitive workflows. The issue is severe on affected devices, but current evidence does not show broad product impact or active exploitation.

Technical view

CVE-2018-14993 concerns com.asus.splendidcommandagent version 1.2.0.18_160928 exposing SplendidCommandAgentService. The CVE states any co-located app can submit arbitrary commands executed as system user on the specified ASUS build fingerprints, enabling broad device compromise behaviors.

Likely exposure

Exposure appears limited to the exact ASUS Zenfone V Live and ASUS ZenFone 3 Max builds named in the CVE. The bundle does not provide CPEs, CVSS, patch levels, or broader model coverage, so managers should verify against device inventory and vendor firmware records.

Exploitation context

The CVE describes local exploitation by a malicious app already installed on the device, including a zero-permission app. KEV is false in the provided bundle, and no cited source here confirms active exploitation in the wild.

Researcher notes

The evidence is precise about package, service, version, and two build fingerprints, but incomplete on remediation and scoring. Treat claims beyond those devices as unverified unless confirmed by vendor advisories or firmware analysis.

Mitigation direction

  • Inventory ASUS Android devices and match model, build fingerprint, and package version.
  • Check ASUS or carrier firmware guidance for patched builds or replacement advice.
  • Remove affected devices from sensitive use if no supported update exists.
  • Restrict sideloading and untrusted app installation on managed Android devices.
  • Apply MDM controls to isolate or retire unsupported affected devices.

Validation and detection

  • Confirm whether fleet devices match the exact affected build fingerprints.
  • Check for com.asus.splendidcommandagent version 1.2.0.18_160928 on suspect devices.
  • Review MDM inventory for ASUS Zenfone V Live and ZenFone 3 Max devices.
  • Verify firmware update status with ASUS or carrier support records.
  • Assess whether affected devices handle corporate credentials, SMS, notifications, or sensitive apps.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-14993 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.