Possible Out of Bounds Stack Write in Bluetooth Function Could Lead to Remote Escalation of Privilege
CVE-2018-9475
8.8HIGH
What is CVE-2018-9475?
The vulnerability in the Android Bluetooth stack, specifically in the HeadsetInterface::ClccResponse method of the btif_hf.cc file, presents a potential risk through a missing bounds check, creating an opportunity for an out of bounds stack write. This flaw could allow adversaries to escalate privileges remotely by exploiting the vulnerability during SIP calls, thus requiring no additional execution privileges or user interaction for successful exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Android 7
Android 8
Android 8.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved