CVE-2019-0128

CWE-2643 documents3 sources
Severity
7.8HIGH
EPSS
0.2%
top 63.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 24

Description

Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m77g-j8m8-3c85: Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 102022-05-24
CVEList
CVE-2019-0128: Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 102019-06-13