Buffer overflow in Intel Ethernet 700 Series and Intel Ethernet 700 Series Controller Software - CVE-2019-0145
Published: November 25, 2019
Vulnerability identifier: #VU22951
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0145
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the target system.
The vulnerability exists due to a boundary error in i40e driver. A local user can trigger memory corruption and escalate privileges on the target system.
Affected software
Intel Ethernet 700 Series
Intel Ethernet 700 Series Controller Software
Intel Ethernet 700 Series Controller Software
How to mitigate CVE-2019-0145
Install updates from vendor's website.
Intel Ethernet 700 Series - update to 7.0
Intel Ethernet 700 Series Controller Software - update to 24.0
Intel Ethernet 700 Series Controller Software - update to 24.0