CVE-2018-9584: High severity Google Android vulnerability
In nfcncifsetconfigstatus of nfcncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-114047681.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Devices running the listed Android versions—7.0, 7.1.1, 7.1.2, 8.0, 8.1, or 9—are the affected population identified in the available data.
What access does an attacker need to exploit it?
Exploitation requires local access and low privileges. No user interaction or additional execution privileges are required.
What is the potential impact of successful exploitation?
A successful exploit can cause an out-of-bounds write and lead to local escalation of privilege, with high confidentiality, integrity, and availability impact according to the provided CVSS vector.