CVE-2018-9411 is an out-of-bounds write vulnerability in the ClearKeyCasPlugin.cpp component of Google Android, stemming from a missing bounds check during decryption. This critical flaw allows for remote arbitrary code execution without requiring elevated privileges, though user interaction is necessary for successful exploitation. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 93/100, the vulnerability poses a significant threat, enabling high impact to confidentiality, integrity, and availability. Despite its severity and community discussion, there is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog as being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.