CVE-2018-9466: High severity IBM Cognos Analytics vulnerability
Google Android could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the Android runtime library. By using a specially-crafted payload, an attacker could exploit this vulnerability to execute arbitrary code in the context of an unprivileged process.
Other sources
In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9466?
CVE-2018-9466 has a high severity rating due to its potential to allow remote code execution on affected devices.
How do I fix CVE-2018-9466?
To fix CVE-2018-9466, update to the latest patched version of the affected software as provided by your vendor.
Which versions of Google Android are impacted by CVE-2018-9466?
CVE-2018-9466 affects Google Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
Is IBM Cognos Analytics affected by CVE-2018-9466?
Yes, IBM Cognos Analytics versions up to 12.0.2 and 11.2.4 FP3 are also affected by CVE-2018-9466.
Can CVE-2018-9466 be exploited through unprivileged processes?
Yes, CVE-2018-9466 can be exploited to execute arbitrary code in the context of unprivileged processes.