Intel Patches Three High-Severity Vulnerabilities

Peter Reutemann <[email protected]> Mon, 19 Aug 2019 11:42:36 +1200
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+9-N9sUGWQjLqa0otqy07YtTveTLMy3fpykxunTPXLpQ@mail.gmail.com>
'Intel's latest patches "stomped out three high-severity
vulnerabilities and five medium-severity flaws," reports Threatpost:

One of the more serious vulnerabilities exist in the Intel Processor
Identification Utility for Windows, free software that users can
install on their Windows machines to identify the actual specification
of their processors. The flaw (CVE-2019-11163) has a score of 8.2 out
of 10 on the CVSS scale, making it high severity. It stems from
insufficient access control in a hardware abstraction driver for the
software, versions earlier than 6.1.0731. This glitch "may allow an
authenticated user to potentially enable escalation of privilege,
denial of service or information disclosure via local access"
according to Intel. Users are urged to update to version 6.1.0731.

Intel stomped out another high-severity vulnerability in its Computing
Improvement Program, which is program that Intel users can opt into
that uses information about participants' computer performance to make
product improvement and detect issues. However, the program contains a
flaw (CVE-2019-11162) in the hardware abstraction of the SEMA driver
that could allow escalation of privilege, denial of service or
information disclosure...

A final high-severity flaw was discovered in the system firmware of
the Intel NUC (short for Next Unit of Computing), a mini-PC kit used
for gaming, digital signage and more. The flaw (CVE-2019-11140) with a
CVSS score of 7.5 out of 10, stems from insufficient session
validation in system firmware of the NUC. This could enable a user to
potentially enable escalation of privilege, denial of service and
information disclosure. An exploit of the flaw would come with
drawbacks -- a bad actor would need existing privileges and local
access to the victim system.

The article notes that the patches "come on the heels of a new type of
side-channel attack revealed last week impacting millions of newer
Intel microprocessors manufactured after 2012."'

-- source: https://it.slashdot.org/story/19/08/18/0030201

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug