ASA-2019-00340 – Intel Chipset Device Software: Improper permissions in the installer


Allele Security Alert

ASA-2019-00340

Identifier(s)

ASA-2019-00340, CVE-2019-0128, INTEL-SA-00224

Title

Improper permissions in the installer

Vendor(s)

Intel

Product(s)

Intel® Chipset Device Software (INF Update Utility)

Affected version(s)

Intel® Chipset Device Software (INF Update Utility) before version 10.1.1.45

Fixed version(s)

Intel® Chipset Device Software (INF Update Utility) version 10.1.1.45 or later

Proof of concept

Unknown

Description

Improper permissions in the installer for Intel Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.

Technical details

Unknown

Credits

Marius Gabriel Mihai

Reference(s)

Intel® Chipset Device Software (INF Update Utility) Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00224.html

Intel® Chipset Device Software (INF Update Utility)
https://downloadcenter.intel.com/download/28768?v=t

CVE-2019-0128
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0128

CVE-2019-0128
https://nvd.nist.gov/vuln/detail/CVE-2019-0128

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 14, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.