First published: Tue Sep 04 2018(Updated: )
Google Android could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the Android runtime library. By using a specially-crafted payload, an attacker could exploit this vulnerability to execute arbitrary code in the context of an unprivileged process.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.2 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP3 | |
Android | ||
Android | =7.0 | |
Android | =7.1.1 | |
Android | =7.1.2 | |
Android | =8.0 | |
Android | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9466 has a high severity rating due to its potential to allow remote code execution on affected devices.
To fix CVE-2018-9466, update to the latest patched version of the affected software as provided by your vendor.
CVE-2018-9466 affects Google Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Yes, IBM Cognos Analytics versions up to 12.0.2 and 11.2.4 FP3 are also affected by CVE-2018-9466.
Yes, CVE-2018-9466 can be exploited to execute arbitrary code in the context of unprivileged processes.