HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2019-0164

CVSS 7.3v3.1pub. 2019-06-13upd. 2024-11-21

Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Intel Turbo Boost Max Technology 3.0

    APP
    Intel
    ≤ 1.0.0.1035
  • Lenovo Thinkstation P410

    HW
    Lenovo
    all versions
  • Lenovo Thinkstation P410 Firmware

    OS
    Lenovo
    all versions
  • Lenovo Thinkstation P510

    HW
    Lenovo
    all versions
  • Lenovo Thinkstation P510 Firmware

    OS
    Lenovo
    all versions
  • Lenovo Thinkstation P710

    HW
    Lenovo
    all versions
  • Lenovo Thinkstation P710 Firmware

    OS
    Lenovo
    all versions
  • Lenovo Thinkstation P910

    HW
    Lenovo
    all versions
  • Lenovo Thinkstation P910 Firmware

    OS
    Lenovo
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-6190MEDIUM5.0same product

Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Len...

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2017-5689CRITICAL9.8⚠ KEVPL ✓same vendor

Privilege Escalation w Intel AMT/ISM/SBT — nieautoryzowany dostęp systemowy

CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)