ID

VAR-201809-0103


CVE

CVE-2018-12162


TITLE

Windows for Intel OpenVINO Toolkit Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-013146

DESCRIPTION

Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access. Intel OpenVINO Toolkit for Windows is a Windows-based toolkit for developing multi-platform computer vision solutions developed by Intel Corporation. There is a security vulnerability in versions of the Windows-based Intel OpenVINO Toolkit prior to 2018.1.265

Trust: 1.8

sources: NVD: CVE-2018-12162 // JVNDB: JVNDB-2018-013146 // VULHUB: VHN-122094 // VULMON: CVE-2018-12162

AFFECTED PRODUCTS

vendor:intelmodel:openvino toolkitscope:ltversion:2018.1.265

Trust: 1.8

sources: JVNDB: JVNDB-2018-013146 // NVD: CVE-2018-12162

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-12162
value: HIGH

Trust: 1.0

NVD: CVE-2018-12162
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201809-614
value: HIGH

Trust: 0.6

VULHUB: VHN-122094
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-12162
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-12162
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-122094
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-12162
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-122094 // VULMON: CVE-2018-12162 // JVNDB: JVNDB-2018-013146 // CNNVD: CNNVD-201809-614 // NVD: CVE-2018-12162

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:CWE-264

Trust: 0.8

sources: VULHUB: VHN-122094 // JVNDB: JVNDB-2018-013146 // NVD: CVE-2018-12162

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-614

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201809-614

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013146

PATCH

title:INTEL-SA-00172url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00172.html

Trust: 0.8

title:Intel OpenVINO Toolkit for Windows Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84873

Trust: 0.6

sources: JVNDB: JVNDB-2018-013146 // CNNVD: CNNVD-201809-614

EXTERNAL IDS

db:NVDid:CVE-2018-12162

Trust: 2.6

db:JVNDBid:JVNDB-2018-013146

Trust: 0.8

db:CNNVDid:CNNVD-201809-614

Trust: 0.7

db:VULHUBid:VHN-122094

Trust: 0.1

db:VULMONid:CVE-2018-12162

Trust: 0.1

sources: VULHUB: VHN-122094 // VULMON: CVE-2018-12162 // JVNDB: JVNDB-2018-013146 // CNNVD: CNNVD-201809-614 // NVD: CVE-2018-12162

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00172.html

Trust: 1.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-12162

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-12162

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/732.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-122094 // VULMON: CVE-2018-12162 // JVNDB: JVNDB-2018-013146 // CNNVD: CNNVD-201809-614 // NVD: CVE-2018-12162

SOURCES

db:VULHUBid:VHN-122094
db:VULMONid:CVE-2018-12162
db:JVNDBid:JVNDB-2018-013146
db:CNNVDid:CNNVD-201809-614
db:NVDid:CVE-2018-12162

LAST UPDATE DATE

2024-11-23T22:17:19.408000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-122094date:2019-10-03T00:00:00
db:VULMONid:CVE-2018-12162date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-013146date:2019-02-15T00:00:00
db:CNNVDid:CNNVD-201809-614date:2019-10-23T00:00:00
db:NVDid:CVE-2018-12162date:2024-11-21T03:44:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-122094date:2018-09-12T00:00:00
db:VULMONid:CVE-2018-12162date:2018-09-12T00:00:00
db:JVNDBid:JVNDB-2018-013146date:2019-02-15T00:00:00
db:CNNVDid:CNNVD-201809-614date:2018-09-13T00:00:00
db:NVDid:CVE-2018-12162date:2018-09-12T19:29:01.497