Intel Patches High-Severity Privilege-Escalation Bugs
#1
Quote:Intel on Tuesday patched three high-severity vulnerabilities that could allow the escalation of privileges across an array of products. Overall, the chip giant fixed five bugs – three rated high-severity, and two medium-severity.

The most concerning of these bugs is an escalation-of-privilege glitch in Intel’s PROset/Wireless Wi-Fi software, which is its wireless connection management tool. The vulnerability, CVE-2018-12177, has a “high” CVSS score of 7.8, according to Intel’s update.

The other high-severity bug exists in the company’s System Support Utility for Windows, which offers support for Intel-packed Windows device users. This bug (CVE-2019-0088) is due to insufficient path checking in the support utility, allowing an already-authenticated user to potentially gain escalation of privilege via local access. The vulnerability has a CVSS score of 7.5.

The high-severity flaw in SGX (CVE-2018-18098) has a CVSS score of 7.5 and could allow an attacker with local access to gain escalated privileges. The vulnerability is rooted in improper file verification in the install routine for Intel’s SGX SDK and Platform Software for Windows before 2.2.100.  It was discovered by researcher Saif Allah ben Massaoud.

Intel’s patch comes during a busy patch Tuesday week, which includes fixes from Adobe and Microsoft.

Source: https://threatpost.com/intel-patches-pri...gs/140665/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Intel Patches High-Severity Privilege-Escalation Bugs - by silversurfer - 09 January 19, 17:52

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19
JEDEC publishes UFS 5.0 spec with up to ...
KIOXIA starts samp...harlan4096 — 08:17
QOwnNotes
26.2.15  Fix Qt5 ...Kool — 07:30

[-]
Birthdays
Today's Birthdays
avatar (50)daadAmomo
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (51)Claudestync
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>