PT-2019-11457 · Lawrence Livermore National Laboratory · Msr-Safe

Published

2019-07-18

·

Updated

2020-08-24

·

CVE-2019-1010066

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Lawrence Livermore National Laboratory msr-safe version 1.1.0
Description: The issue is related to incorrect access control, allowing an attacker to modify model specific registers. This is due to a bug in the ioctl interface whitelist checking, which can be exploited to write to these registers, a function normally reserved for the root user. The component affected is ioctl handling.
Recommendations: For version 1.1.0, update to version 1.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the ioctl interface to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010066

Affected Products

Msr-Safe