cbcvebase.
CVE-2018-9411
published 2024-11-19

CVE-2018-9411: In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution…

PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.55%
42.2th percentile
In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.

Affected

5 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the `decrypt` function of `ClearKeyCasPlugin.cpp`; monitor for exploitation attempts targeting this component in Android media/CAS subsystem on AOSP versions 8.0 and 8.1
  • CVE-2018-9411 is rated CRITICAL RCE with no privileges required; prioritize detection on Android 8.0 and 8.1 devices where user interaction (e.g., media playback) could trigger the vulnerability
  • ·Exploitation requires user interaction (e.g., opening a malicious media file); no additional execution privileges are needed beyond that interaction
  • ·Only AOSP versions 8.0 and 8.1 are listed as affected; patch reference is Android bug A-79376389 per the July 2018 security bulletin
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.