CVE-2018-12209Incorrect Permission Assignment in Corporation Intel Graphics Driver FOR Windows

Severity
3.3LOWNVD
EPSS
0.1%
top 72.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 13

Description

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to read device configuration information via local access.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDintel/graphics_driver23 versions+22

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3rfm-qg29-8hqw: Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 102022-05-13
CVEList
CVE-2018-12209: Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 102019-03-14
CVE-2018-12209 — Incorrect Permission Assignment | cvebase