CVE-2018-9585: High severity Google Android vulnerability
In nfcncifprocgetrouting of nfcncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-117554809.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation requires local access with low privileges. No user interaction or additional execution privileges are required.
What is the likely impact if exploitation succeeds?
The issue can enable local escalation of privilege. The CVSS vector indicates potential high impact to confidentiality, integrity, and availability.
Which Android releases are identified as affected?
The affected releases listed are Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
Is a fix available?
Yes. A patch is available, and the issue is tracked as Android ID A-117554809.