PT-2019-1662 · Intel · Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor+1

Publicado

2019-03-12

·

Atualizado

2019-10-03

·

CVE-2018-12205

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel Core Processor Platform Sample/Silicon Reference firmware for 8th Generation Intel Core Processor Intel Core Processor Platform Sample/Silicon Reference firmware for 7th Generation Intel Core Processor
Description The issue is related to inadequate access control and improper certificate validation in the firmware. This could potentially allow an unauthenticated user with physical access to escalate privileges. The exploitation of this issue may enable an attacker to execute arbitrary code.
Recommendations For 8th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls. For 7th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls. As a temporary workaround, consider restricting physical access to the devices until a patch is available.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01210
CVE-2018-12205

Produtos afetados

Intel Core Processor Platform Sample/Silicon Reference Firmware For 7Th Generation Intel Core Processor
Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor