Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-4419


Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.


Published

2009-12-24T17:30:00.250

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-16

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware intel gm45_chipset * Yes
Hardware intel pm45_express_chipset * Yes
Hardware intel q35_chipset * Yes
Hardware intel q43_express_chipset * Yes
Hardware intel q45_chipset * Yes

References