CVE-2018-12217Incorrect Permission Assignment in Corporation Intel Graphics Driver FOR Windows

Severity
2.3LOWNVD
EPSS
0.1%
top 70.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 13

Description

Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to read device configuration information via local access.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 0.8 | Impact: 1.4

Affected Packages2 packages

NVDintel/graphics_driver23 versions+22

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g7xm-cj56-xvpv: Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 102022-05-13
CVEList
CVE-2018-12217: Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 102019-03-14
CVE-2018-12217 — Incorrect Permission Assignment | cvebase