ASA-2019-00335 – Intel Omni-Path Fabric Manager GUI: Improper permissions in the installer


Allele Security Alert

ASA-2019-00335

Identifier(s)

ASA-2019-00335, CVE-2019-11117, INTEL-SA-00257

Title

Improper permissions in the installer

Vendor(s)

Intel

Product(s)

Intel® Omni-Path Fabric Manager GUI

Affected version(s)

Intel® Omni-Path Fabric Manager GUI before version 10.9.2.1.1

Fixed version(s)

Intel® Omni-Path Fabric Manager GUI version 10.9.2.1.1 or later

Proof of concept

Unknown

Description

Improper permissions in the installer for Intel(R) Omni-Path Fabric Manager GUI before version 10.9.2.1.1 may allow an authenticated user to potentially enable escalation of privilege via local attack.

Technical details

Unknown

Credits

Marius Gabriel Mihai

Reference(s)

Intel® Omni-Path Fabric Manager GUI Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00257.html

Intel® Omni-Path Fabric Manager GUI
https://downloadcenter.intel.com/download/28784/Intel-Omni-Path-Fabric-Manager-GUI?product=92003

CVE-2019-11117
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11117

CVE-2019-11117
https://nvd.nist.gov/vuln/detail/CVE-2019-11117

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 12, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.