CVE-2018-9490
CVE-2018-9490
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
02 out 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111274046
Produtos afetados
Google Inc. · AndroidQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://android.googlesource.com/platform/external/chromium-libpac/+/948d4753664cc4e6b33cc3de634ac8fd5f781382%2Chttps://android.googlesource.com/platform/external/v8/+/a24543157ae2cdd25da43e20f4e48a07481e6cebhttps://source.android.com/security/bulletin/2018-10-01%2Chttp://www.securityfocus.com/bid/105484