CVE-2018-9397 is an out-of-bounds write vulnerability in the MTK WMT device driver, specifically within the WMT_unlocked_ioctl function, affecting Google Android devices. This flaw allows for local escalation of privilege, granting System execution privileges to an attacker who already possesses high privileges. The vulnerability has a CVSS score of 6.7 (Medium) due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring no user interaction for exploitation. There is currently no public exploit code available, nor is it listed in the CISA KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.