ID

VAR-202008-1143


CVE

CVE-2020-8743


TITLE

Intel(R) Mailbox Interface driver Vulnerability regarding improper default permissions in

Trust: 0.8

sources: JVNDB: JVNDB-2020-009511

DESCRIPTION

Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. Intel(R) Mailbox Interface driver There is a vulnerability in improper default permissions.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. There is a security vulnerability in the installer of the Intel Mailbox Interface, which is caused by the program not being properly authorized. An attacker could exploit this vulnerability to elevate privileges

Trust: 1.71

sources: NVD: CVE-2020-8743 // JVNDB: JVNDB-2020-009511 // VULHUB: VHN-186868

AFFECTED PRODUCTS

vendor:intelmodel:mailbox interface driverscope:eqversion:*

Trust: 1.0

vendor:intelmodel:mailbox interface driverscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-009511 // NVD: CVE-2020-8743

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8743
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-009511
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202008-732
value: HIGH

Trust: 0.6

VULHUB: VHN-186868
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-8743
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009511
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-186868
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8743
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009511
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-186868 // JVNDB: JVNDB-2020-009511 // CNNVD: CNNVD-202008-732 // NVD: CVE-2020-8743

PROBLEMTYPE DATA

problemtype:CWE-276

Trust: 1.9

sources: VULHUB: VHN-186868 // JVNDB: JVNDB-2020-009511 // NVD: CVE-2020-8743

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202008-732

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202008-732

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009511

PATCH

title:INTEL-SA-00394url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00394.html

Trust: 0.8

sources: JVNDB: JVNDB-2020-009511

EXTERNAL IDS

db:NVDid:CVE-2020-8743

Trust: 2.5

db:JVNid:JVNVU99606488

Trust: 0.8

db:JVNDBid:JVNDB-2020-009511

Trust: 0.8

db:CNNVDid:CNNVD-202008-732

Trust: 0.7

db:VULHUBid:VHN-186868

Trust: 0.1

sources: VULHUB: VHN-186868 // JVNDB: JVNDB-2020-009511 // CNNVD: CNNVD-202008-732 // NVD: CVE-2020-8743

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00394.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-8743

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8743

Trust: 0.8

url:https://jvn.jp/vu/jvnvu99606488

Trust: 0.8

sources: VULHUB: VHN-186868 // JVNDB: JVNDB-2020-009511 // CNNVD: CNNVD-202008-732 // NVD: CVE-2020-8743

SOURCES

db:VULHUBid:VHN-186868
db:JVNDBid:JVNDB-2020-009511
db:CNNVDid:CNNVD-202008-732
db:NVDid:CVE-2020-8743

LAST UPDATE DATE

2024-11-23T21:35:21.370000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-186868date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009511date:2020-11-10T07:39:53
db:CNNVDid:CNNVD-202008-732date:2021-01-05T00:00:00
db:NVDid:CVE-2020-8743date:2024-11-21T05:39:22.003

SOURCES RELEASE DATE

db:VULHUBid:VHN-186868date:2020-08-13T00:00:00
db:JVNDBid:JVNDB-2020-009511date:2020-11-10T07:39:53
db:CNNVDid:CNNVD-202008-732date:2020-08-12T00:00:00
db:NVDid:CVE-2020-8743date:2020-08-13T03:15:16.587