Lucene search

K
cve[email protected]CVE-2008-7096
HistoryAug 27, 2009 - 8:30 p.m.

CVE-2008-7096

2009-08-2720:30:00
CWE-264
web.nvd.nist.gov
25
cve-2008-7096
intel
bios
firmware
vulnerability
local admins
privileges

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%

Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.

Affected configurations

NVD
Node
intelbiosMatchdg33bu
OR
intelbiosMatchdg33fb
OR
intelbiosMatchdg33tl
OR
intelbiosMatchdp35dp
OR
intelbiosMatchdq35jo
OR
intelbiosMatchdq35mp
OR
intelbiosMatchdx38bt
OR
intelbiosMatchmgm965tw

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%

Related for CVE-2008-7096