#VU45705 Heap-based Buffer Overflow in Intel products - CVE-2020-8730

 

#VU45705 Heap-based Buffer Overflow in Intel products - CVE-2020-8730

Published: August 14, 2020


Vulnerability identifier: #VU45705
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-8730
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Intel Server System R1000WT
Intel Server System R2000WT
Intel Server Boards S2600WT
Intel Server Board S2600CW
Intel Compute Module HNS2600KP
Intel Server Board S2600KP
Intel Compute Module HNS2600TP
Intel Server Board S2600TP
Intel Server System R1000SP
Intel Server System LSVRP
Intel Server System LR1304SP
Intel Server Board S1200SP
Intel Server System R1000WF
Intel Server System R2000WF
Intel Server Board S2600WF
Intel Server Board S2600ST
Intel Compute Module HNS2600BP
Intel Server Board S2600BP
Software vendor:
Intel

Description

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A local user can pass specially crafted data to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links