PT-2020-6386 · Intel · Intel(R) Rwc3 For Windows

Clavoillotte

·

Published

2020-02-11

·

Updated

2020-02-24

·

CVE-2020-0564

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) RWC3 for Windows versions prior to 7.010.009.000
Description The issue is related to improper permissions in the installer, which may allow an authenticated user to potentially enable escalation of privilege via local access. It is also described as a vulnerability in the default permission settings of the Intel Raid Web Console 3, which can be exploited to elevate privileges.
Recommendations For versions prior to 7.010.009.000, update to version 7.010.009.000 or later to resolve the issue. As a temporary workaround, consider restricting local access to the installer until a patch is applied.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04427
CVE-2020-0564

Affected Products

Intel(R) Rwc3 For Windows