PT-2021-2094 · Intel · Intel Graphics Drivers+1

Linshuang Li

·

Published

2021-02-09

·

Updated

2021-02-23

·

CVE-2020-24450

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Intel(R) Graphics Drivers versions prior to 26.20.100.8141 Intel(R) Graphics Drivers versions prior to 15.45.32.5145 Intel(R) Graphics Drivers versions prior to 15.40.46.5144 Server Board Onboard Video Driver (affected versions not specified)
Description: The issue is related to an improper conditions check in some Intel(R) Graphics Drivers, which may allow an authenticated user to potentially enable escalation of privilege via local access. This is also associated with incorrect path handling in the firmware installer of the Server Board Onboard Video Driver for Windows, which could allow an attacker to elevate their privileges.
Recommendations: For Intel(R) Graphics Drivers versions prior to 26.20.100.8141, update to version 26.20.100.8141 or later. For Intel(R) Graphics Drivers versions prior to 15.45.32.5145, update to version 15.45.32.5145 or later. For Intel(R) Graphics Drivers versions prior to 15.40.46.5144, update to version 15.40.46.5144 or later. For Server Board Onboard Video Driver, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Check for Exceptional Conditions

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00946
CVE-2020-24450

Affected Products

Intel Graphics Drivers
Server Board Onboard Video Driver