Buffer overflow in Intel products - CVE-2019-11151

 

Buffer overflow in Intel products - CVE-2019-11151

Published: November 26, 2019


Vulnerability identifier: #VU22980
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-11151
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Intel
Affected software:
Intel Wi-Fi 6 AX201
Intel Wi-Fi 6 AX200
Intel Wireless-AC 9560
Intel Wireless-AC 9462
Intel Wireless-AC 9461
Intel Wireless-AC 9260
Intel Dual Band Wireless-AC 8265
Intel Dual Band Wireless-AC 8260
Intel Dual Band Wireless-AC 3168
Intel Wireless 7265 (Rev D) Family
Intel Dual Band Wireless-AC 3165
Intel WIFI Drivers

Detailed vulnerability description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to a boundary error. A local user can trigger memory corruption and enable escalation of privilege, denial of service and information disclosure.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2019-11151

Install updates from vendor's website.

Sources