CVE-2018-9445: Path Traversal
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80436257.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9445?
CVE-2018-9445 is classified as a high-severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2018-9445?
To resolve CVE-2018-9445, it is recommended to apply the latest security patches provided for affected Android versions.
Which Android versions are affected by CVE-2018-9445?
CVE-2018-9445 impacts Android versions 6.0 through 8.1.
Can CVE-2018-9445 be exploited without user interaction?
Yes, CVE-2018-9445 can be exploited without any user interaction.
What kind of vulnerability is CVE-2018-9445?
CVE-2018-9445 is a path traversal vulnerability that may lead to privilege escalation.