Lucene search

K
intelIntel Security CenterINTEL:INTEL-SA-00209
HistoryMar 10, 2023 - 12:00 a.m.

Intel® System Defense Utility Vulnerability Advisory

2023-03-1000:00:00
Intel Security Center
www.intel.com
8
intel
system defense utility
security vulnerability
denial of service
discontinuation
uninstall
coordinated disclosure

0.0004 Low

EPSS

Percentile

12.8%

Summary:

A potential security vulnerability in the Intel® System Defense Utility (all versions) may allow for a denial of service. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation notice for the System Defense Utility.

Vulnerability Details:

CVEID: CVE-2018-3705

Description: Improper directory permissions in the installer for the Intel® System Defense Utility may allow authenticated users to potentially enable a denial of service via local access.

CVSS Base Score: 4.6 Medium

CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:L

Affected Products:

Intel® System Defense Utility all versions

Recommendations:

Intel has issued a Product Discontinuation notice for Intel® System Defense Utility and recommends that users of the Intel® System Defense Utility uninstall it or discontinue use at their earliest convenience.

Acknowledgements:

This issue was found externally.

Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are deployed.

0.0004 Low

EPSS

Percentile

12.8%

Related for INTEL:INTEL-SA-00209