PT-2019-11457 · Lawrence Livermore National Laboratory · Msr-Safe

Publicado

2019-07-18

·

Atualizado

2020-08-24

·

CVE-2019-1010066

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Lawrence Livermore National Laboratory msr-safe version 1.1.0
Description: The issue is related to incorrect access control, allowing an attacker to modify model specific registers. This is due to a bug in the ioctl interface whitelist checking, which can be exploited to write to these registers, a function normally reserved for the root user. The component affected is ioctl handling.
Recommendations: For version 1.1.0, update to version 1.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the ioctl interface to minimize the risk of exploitation.

Exploit

Correção

Missing Authorization

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1010066

Produtos afetados

Msr-Safe