| Vulnerability Name: | CVE-2008-7096 (CCN-44676) | ||||||||
| Assigned: | 2008-08-25 | ||||||||
| Published: | 2008-08-25 | ||||||||
| Updated: | 2017-08-17 | ||||||||
| Summary: | Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3. | ||||||||
| CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.9 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-7096 Source: MISC Type: UNKNOWN http://invisiblethingslab.com/bh08/part2-full.pdf Source: OSVDB Type: UNKNOWN 49901 Source: CCN Type: INTEL-SA-00017 Intel Desktop and Intel Mobile Boards Privilege Escalation Source: CONFIRM Type: Patch, Vendor Advisory http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00017&languageid=en-fr Source: MISC Type: UNKNOWN http://theinvisiblethings.blogspot.com/2008/08/attacking-xen-domu-vs-dom0.html Source: MISC Type: UNKNOWN http://theinvisiblethings.blogspot.com/2008/08/intel-patches-q35-bug.html Source: CCN Type: OSVDB ID: 49901 Intel Mobile Boards System Management Mode Local Privilege Escalation Source: BID Type: UNKNOWN 30823 Source: CCN Type: BID-30823 Intel System Management Mode Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN intel-bios-smm-privilege-escalation(44676) Source: XF Type: UNKNOWN intel-bios-smm-privilege-escalation(44676) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||