CVE-2018-11914

HIGH

Android - Improper Access Control

Title source: llm
STIX 2.1

Description

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /systemrw/ which presents a potential security.

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
google/android
Published Nov 27, 2018
Tracked Since Feb 18, 2026