Possible Out of Bounds Write in ImsaClient.cpp and VideoTelephony.c Could Lead to Local Escalation of Privilege
CVE-2018-9366

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2018-9366?

A potential out of bounds write vulnerability exists in the IMSA Client of the Android operating system, specifically within the IMSA_Recv_Thread and VT_IMCB_Thread functions implemented in ImsaClient.cpp and VideoTelephony.c. This issue arises due to an integer overflow that could allow an attacker to execute code with elevated privileges locally. Notably, the exploitation of this vulnerability does not require any additional permissions or user interaction, making it particularly concerning for system integrity. System administrators and users are advised to implement the necessary updates to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android SoCVersion

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.