Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44403
HistoryNov 28, 2023 - 3:55 a.m.

Privilege Escalation

2023-11-2803:55:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
intel-microcode
vulnerability
privilege escalation
processor instructions
intel processors
authenticated user
escalation of privilege
information disclosure
denial of service
local access
software

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%

intel-microcode is vulnerable to Privilege Escalation. The vulnerability exists due to a sequence of processor instructions that results in unexpected behavior for certain Intelยฎ Processors. An authenticated user may exploit this issue to potentially enable escalation of privilege, information disclosure, and/or denial of service via local access.

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%