Buffer overflow in Intel Thunderbolt DCH drivers - CVE-2020-12325

 

Buffer overflow in Intel Thunderbolt DCH drivers - CVE-2020-12325

Published: November 12, 2020


Vulnerability identifier: #VU48393
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12325
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error. A local user can trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Intel Thunderbolt DCH drivers

How to mitigate CVE-2020-12325

Install updates from vendor's website.

Intel Thunderbolt DCH drivers - update to 72

External References

Related Security Bulletins