CVE-2019-14574
published 2019-11-14CVE-2019-14574: Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
21.5th percentile
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | < 26.20.100.7209 | 26.20.100.7209 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in Intel IGC64 graphics driver
blogs_talos·2019-11-13·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability in Intel IGC64 graphics driver
## Vulnerability Spotlight: Denial-of-service vulnerability in Intel IGC64 graphics driver
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Intel’s IGC64.dll graphics driver contains a denial-of-service vulnerability. An attacker could exploit this bug by supplying a malformed pixel shader if the graphics driver is operating inside a VMware
guest operating system. This type of attack can be triggered from VMware guest usermode to cause a denial-of-service attack due to an out-of-bounds read in the driver.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Intel to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details Intel IGC64.DLL shader functionality DCL_INDEXAB
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in Intel IGC64 graphics driver
blogs_talos·2019-11-13·CVSS 5.5
[MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability in Intel IGC64 graphics driver
Piotr Bania of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Intel’s IGC64.dll graphics driver contains a denial-of-service vulnerability. An attacker could exploit this bug by supplying a malformed pixel shader if the graphics driver is operating inside a VMware
guest operating system. This type of attack can be triggered from VMware guest usermode to cause a denial-of-service attack due to an out-of-bounds read in the driver.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Intel to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsIntel IGC64.DLL shader functionality DCL_INDEXABLE_TEMP denial-of-service vulnerability (TALOS-2019-0845/CVE-2019-14574)
An exploitable mem
2019-11-14
Published