ID

VAR-201809-0094


CVE

CVE-2018-12148


TITLE

Intel Driver and Support Assistant Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-010519

DESCRIPTION

Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access. Intel Driver and Support Assistant is an Intel driver and support management tool of Intel Corporation. This tool is mainly used to get the latest applications provided by Intel. A local attacker could exploit this vulnerability to elevate privileges and execute code as an administrator

Trust: 1.71

sources: NVD: CVE-2018-12148 // JVNDB: JVNDB-2018-010519 // VULHUB: VHN-122078

AFFECTED PRODUCTS

vendor:intelmodel:driver \& support assistantscope:ltversion:3.5.0.1

Trust: 1.0

vendor:intelmodel:driver and support assistantscope:ltversion:3.5.0.1

Trust: 0.8

sources: JVNDB: JVNDB-2018-010519 // NVD: CVE-2018-12148

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-12148
value: HIGH

Trust: 1.0

NVD: CVE-2018-12148
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201809-619
value: HIGH

Trust: 0.6

VULHUB: VHN-122078
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-12148
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: CVE-2018-12148
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-122078
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-12148
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-122078 // JVNDB: JVNDB-2018-010519 // CNNVD: CNNVD-201809-619 // NVD: CVE-2018-12148

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-122078 // JVNDB: JVNDB-2018-010519 // NVD: CVE-2018-12148

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-619

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201809-619

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010519

PATCH

title:INTEL-SA-00165url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00165.html

Trust: 0.8

title:Intel Driver and Support Assistant Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84878

Trust: 0.6

sources: JVNDB: JVNDB-2018-010519 // CNNVD: CNNVD-201809-619

EXTERNAL IDS

db:NVDid:CVE-2018-12148

Trust: 2.5

db:JVNDBid:JVNDB-2018-010519

Trust: 0.8

db:CNNVDid:CNNVD-201809-619

Trust: 0.7

db:VULHUBid:VHN-122078

Trust: 0.1

sources: VULHUB: VHN-122078 // JVNDB: JVNDB-2018-010519 // CNNVD: CNNVD-201809-619 // NVD: CVE-2018-12148

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00165.html

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-12148

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-12148

Trust: 0.8

sources: VULHUB: VHN-122078 // JVNDB: JVNDB-2018-010519 // CNNVD: CNNVD-201809-619 // NVD: CVE-2018-12148

SOURCES

db:VULHUBid:VHN-122078
db:JVNDBid:JVNDB-2018-010519
db:CNNVDid:CNNVD-201809-619
db:NVDid:CVE-2018-12148

LAST UPDATE DATE

2024-11-23T22:58:55.400000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-122078date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-010519date:2018-12-17T00:00:00
db:CNNVDid:CNNVD-201809-619date:2019-10-08T00:00:00
db:NVDid:CVE-2018-12148date:2024-11-21T03:44:39.487

SOURCES RELEASE DATE

db:VULHUBid:VHN-122078date:2018-09-12T00:00:00
db:JVNDBid:JVNDB-2018-010519date:2018-12-17T00:00:00
db:CNNVDid:CNNVD-201809-619date:2018-09-13T00:00:00
db:NVDid:CVE-2018-12148date:2018-09-12T19:29:00.543