Buffer overflow in Intel products - CVE-2018-3624

 

Buffer overflow in Intel products - CVE-2018-3624

Published: April 24, 2018 / Updated: April 25, 2018


Vulnerability identifier: #VU12169
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-3624
CWE-ID: CWE-120
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Intel
Affected software:
Sofia 3G-R W
Sofia 3G-R
Sofia 3G
Intel XMM74xx
Intel XMM73xx
Intel XMM72xx
Intel XMM71xx

Detailed vulnerability description

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in ETWS processing module. An adjacent attacker can trigger memory corruption and execute arbitrary code via an adjacent network.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2018-3624

Install update from vendor's website.

Sources