CERT-In Vulnerability Note
CIVN-2019-0200
Multiple Vulnerabilities in Intel Products
Original Issue Date:December 16, 2019
Severity Rating: MEDIUM
Systems Affected
- Intel Rapid Storage Technology software before version 17.7.0.1006.
- Intel Xeon Scalable Processor
- Intel Xeon Scalable Processor 2nd Generation
- Intel Xeon D & W Processors
- Intel Core i9 Processors 8th and 9th Generation
- Intel Xeon Processor E3 v5 & v6 Family
- Intel Xeon E Processor
- Intel Core Processors 6th to 10th Generation
Overview
Multiple vulnerabilities have been reported in Intel products which could allow a local attacker to escalate privileges, cause denial of service (DoS) conditions or access sensitive information on a targeted system.
Description
1. Escalation of Privilege Vulnerability in Intel RST
(
CVE-2019-14568
)
This vulnerability exists in the Intel Rapid Storage Technology (RST) due to improper handling of permissions by the affected software. An authenticated attacker could exploit this vulnerability through local access to the system. Successful exploitation of this vulnerability could allow the attacker to get escalated privileges on the targeted system.
2. Vulnerability in multiple Intel Processors
(
CVE-2019-14607
)
This vulnerability exists in multiple Intel Processors due to improper checking of conditions by the firmware. An attacker could exploit these vulnerabilities through local access to the targeted system. Successful exploitation of these vulnerabilities could allow the attacker to get escalated privileges, cause denial of service (DoS) conditions or access sensitive information on a targeted system.
Solution
- For CVE-2019-14568:
Update to Intel RST to version 17.7.0.1006 or later:
https://downloadcenter.intel.com/download/29094/Intel-Rapid-Storage-Technology-Intel-RST-User-Interface-and-Driver?product=55005
- For CVE-2019-14607:
Update to the latest firmware version provided by the system manufacturer.
Vendor Information
Intel
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00324.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00317.html
CVE Name
CVE-2019-14568
CVE-2019-14607
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|