Buffer overflow in Intel products - CVE-2018-3624

 

Buffer overflow in Intel products - CVE-2018-3624

Published: April 24, 2018 / Updated: April 25, 2018


Vulnerability identifier: #VU12169
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3624
CWE-ID: CWE-120
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in ETWS processing module. An adjacent attacker can trigger memory corruption and execute arbitrary code via an adjacent network.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Sofia 3G-R W
Sofia 3G-R
Sofia 3G
Intel XMM74xx
Intel XMM73xx
Intel XMM72xx
Intel XMM71xx

How to mitigate CVE-2018-3624

Install update from vendor's website.


External References

Related Security Bulletins