Memory corruption in Smart Sound Technology - CVE-2018-3666

 

Memory corruption in Smart Sound Technology - CVE-2018-3666

Published: July 26, 2018


Vulnerability identifier: #VU14007
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3666
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to non-paged pool overflow in driver module in Intel Smart Sound Technology. A local attacker can trigger memory corruption and execute arbitrary code with administrative privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Smart Sound Technology

How to mitigate CVE-2018-3666

Update to version 9.21.00.3541 or later.

Smart Sound Technology - update to 9.21.00.3541

External References

Related Security Bulletins