Improper access control in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0142
Published: November 25, 2019
Vulnerability identifier: #VU22948
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0142
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in "ilp60x64.sys" driver. A local user can bypass implemented security restrictions and escalate privileges on the target system.
Affected software
Intel Ethernet 700 Series
Intel Ethernet 700 Series Controller Software
Intel Ethernet 700 Series Controller Software
How to mitigate CVE-2019-0142
Install updates from vendor's website.
Intel Ethernet 700 Series - update to 1.33.0.0
Intel Ethernet 700 Series Controller Software - update to 24.0
Intel Ethernet 700 Series Controller Software - update to 24.0