Memory Corruption Vulnerability in Download.c Leads to Local Escalation of Privilege
CVE-2018-9370

7.3HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
19 November 2024

What is CVE-2018-9370?

A memory corruption vulnerability exists in the Android Download Manager's implementation that enables users to download data directly into memory. This specific mode lacks proper bounds checking, which can lead to potential memory corruptions. As a result, the vulnerability may allow a local user to escalate privileges without the need for additional execution rights. Exploitation requires user interaction, making the impact contingent upon the actions of the affected users. Regular updates and security patches are crucial for mitigating risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android SoCVersion

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.