PT-2020-6386 · Intel · Intel(R) Rwc3 For Windows
Clavoillotte
·
Published
2020-02-11
·
Updated
2020-02-24
·
CVE-2020-0564
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel(R) RWC3 for Windows versions prior to 7.010.009.000
Description
The issue is related to improper permissions in the installer, which may allow an authenticated user to potentially enable escalation of privilege via local access. It is also described as a vulnerability in the default permission settings of the Intel Raid Web Console 3, which can be exploited to elevate privileges.
Recommendations
For versions prior to 7.010.009.000, update to version 7.010.009.000 or later to resolve the issue. As a temporary workaround, consider restricting local access to the installer until a patch is applied.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel(R) Rwc3 For Windows