CVE-2016-5647
published 2016-12-13CVE-2016-5647: The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local…
PriorityP434high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
44.8th percentile
The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | 15.33 – 15.33.42.4358 | — |
| intel | graphics_driver | 15.36 – 15.36.30.4385 | — |
| intel | graphics_driver | 15.40 – 15.40.4404 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Local Code Execution via the Intel HD Graphics Windows Kernel Driver
blogs_talos·2016-07-11·CVSS 7.8
[HIGH] Vulnerability Spotlight: Local Code Execution via the Intel HD Graphics Windows Kernel Driver
This vulnerability was discovered by Piotr Bania.
Talos, in coordination with Intel, is disclosing the discovery of TALOS-2016-0087, a local arbitrary code execution vulnerability within the Intel HD Graphics Windows Kernel Driver. This vulnerability exists in the communication functionality of the driver and can be exploited if a specially crafted message is sent to the driver, resulting in a denial of service or arbitrary code execution. Note that exploitation of this vulnerability is only achievable in local contexts. This vulnerability has been responsibly disclosed to Intel in accordance with our Vulnerability Reporting and Disclosure guidelines.
## Details on TALOS-2016-0087
TALOS-2016-0087 (CVE-2016-5647) is an arbitrary code execution vulnerability in the Intel HD Graphics Kerne
Talos
Vulnerability Spotlight: Local Code Execution via the Intel HD Graphics Windows Kernel Driver
blogs_talos·2016-07-11·CVSS 7.8
[HIGH] Vulnerability Spotlight: Local Code Execution via the Intel HD Graphics Windows Kernel Driver
## Vulnerability Spotlight: Local Code Execution via the Intel HD Graphics Windows Kernel Driver
This vulnerability was discovered by Piotr Bania.
Talos, in coordination with Intel, is disclosing the discovery of TALOS-2016-0087, a local arbitrary code execution vulnerability within the Intel HD Graphics Windows Kernel Driver. This vulnerability exists in the communication functionality of the driver and can be exploited if a specially crafted message is sent to the driver, resulting in a denial of service or arbitrary code execution. Note that exploitation of this vulnerability is only achievable in local contexts. This vulnerability has been responsibly disclosed to Intel in accordance with our Vulnerability Reporting and Disclosure guidelines.
## Details on TALOS-2016-0087
TALOS-201
http://www.securityfocus.com/bid/91708http://www.talosintelligence.com/reports/TALOS-2016-0087/https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00054&languageid=en-frhttps://support.lenovo.com/us/en/product_security/ps500068http://www.securityfocus.com/bid/91708http://www.talosintelligence.com/reports/TALOS-2016-0087/https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00054&languageid=en-frhttps://support.lenovo.com/us/en/product_security/ps500068
2016-12-13
Published