Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
The vulnerability results from improper access control in a driver operating in Linux kernel mode (kernel mode driver). An authenticated local user can exploit this flaw to obtain higher privileges than assigned to them. The attack vector is local, meaning the attacker must have access to a system with the vulnerable driver installed. Due to the lack of detailed mechanism description from the vendor, the exact exploitation method is not publicly known.
Successful exploitation of this vulnerability allows an authenticated local user to perform privilege escalation — potentially obtaining kernel-level operating system privileges. This can lead to complete system takeover, violation of confidentiality, integrity, and availability of both the local system and associated infrastructure.
Update the driver to version 28.3 or later. Detailed information and update files are available in the Intel security advisory INTEL-SA-00918 at: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00918.html
Linux kernel mode driver for Intel Ethernet Network Controllers and Adapters — driver versions before 28.3 (applies to Intel Ethernet 800 Series Controllers Driver)
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XIntel Ethernet 800 Series Controllers Driver
APPIntel< 28.3
Related vulnerabilities
Out-of-bounds write w sterowniku Linux dla Intel Ethernet 800 Series — privilege escalation
Błąd wrap-around w sterowniku Intel Ethernet 800 — privilege escalation
Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Ad...
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup