
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-9411 is a critical security vulnerability discovered in the Android Media Framework component. The vulnerability was disclosed in July 2018 and affects Android versions 8.0 and 8.1. It involves a possible out-of-bounds write due to a missing bounds check in the decrypt function of ClearKeyCasPlugin.cpp (Android Bulletin).
The vulnerability is classified as a Remote Code Execution (RCE) vulnerability with Critical severity. It exists in the decrypt functionality of ClearKeyCasPlugin.cpp where a missing bounds check could lead to an out-of-bounds write condition. The issue affects the Media Framework component of Android operating system (Android Bulletin).
If exploited, this vulnerability could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process on affected Android devices (Android Bulletin).
Google released patches for this vulnerability in the July 2018 Android Security Bulletin. The fix was included in the 2018-07-01 security patch level. Users are advised to update their Android devices to a security patch level of 2018-07-01 or later to address this vulnerability (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."