In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References
| Link | Resource |
|---|---|
| https://source.android.com/security/bulletin/2018-06-01 | Vendor Advisory |
Configurations
History
17 Jun 2026, 02:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) En el bootloader hay un comando fastboot que permite argumentos de línea de comandos del kernel especificados por el usuario. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. Se requiere interacción del usuario para la explotación. |
22 Nov 2024, 21:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
| References | () https://source.android.com/security/bulletin/2018-06-01 - Vendor Advisory | |
| First Time |
Google
Google android |
|
| CWE | NVD-CWE-noinfo |
21 Nov 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
19 Nov 2024, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-19 20:15
Updated : 2026-06-17 02:06
NVD link : CVE-2018-9369
Mitre link : CVE-2018-9369
CVE.ORG link : CVE-2018-9369
JSON object : View
Products Affected
- android
CWE
