Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0164


Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated user to potentially enable escalation of privilege via local access.


Published

2019-06-13T16:29:00.840

Last Modified

2024-11-21T04:16:23.300

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intel turbo_boost_max_technology_3.0 ≤ 1.0.0.1035 Yes
Operating System lenovo thinkstation_p410_firmware - Yes
Hardware lenovo thinkstation_p410 - No
Operating System lenovo thinkstation_p510_firmware - Yes
Hardware lenovo thinkstation_p510 - No
Operating System lenovo thinkstation_p710_firmware - Yes
Hardware lenovo thinkstation_p710 - No
Operating System lenovo thinkstation_p910_firmware - Yes
Hardware lenovo thinkstation_p910 - No

References