CVE-2023-28404

CWE-125Out-of-bounds Read3 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 74.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14

Description

Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 2.0 | Impact: 1.4

Affected Packages3 packages

NVDintel/iris_xe_graphics< 31.0.101.4255
NVDintel/arc_a_graphics< 31.0.101.4255

🔴Vulnerability Details

2
CVEList
CVE-2023-28404: Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 312023-11-14
GHSA
GHSA-v325-cfqv-359p: Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 312023-11-14
CVE-2023-28404 (MEDIUM CVSS 5.5) | Out-of-bounds read in the Intel(R) | cvebase.io