6.9

CVE-2008-7096

Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Bios Version dg33bu
Intel ≫ Bios Version dg33fb
Intel ≫ Bios Version dg33tl
Intel ≫ Bios Version dp35dp
Intel ≫ Bios Version dq35jo
Intel ≫ Bios Version dq35mp
Intel ≫ Bios Version dx38bt
Intel ≫ Bios Version mgm965tw
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.237
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://invisiblethingslab.com/bh08/part2-full.pdf
http://osvdb.org/49901
http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00017&languageid=en-fr
Patch
Vendor Advisory
http://theinvisiblethings.blogspot.com/2008/08/attacking-xen-domu-vs-dom0.html
http://theinvisiblethings.blogspot.com/2008/08/intel-patches-q35-bug.html
http://www.securityfocus.com/bid/30823
https://exchange.xforce.ibmcloud.com/vulnerabilities/44676