Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4419

Опубликовано: 24 дек. 2009
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:h:intel:gm45_chipset:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:pm45_express_chipset:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:q35_chipset:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:q43_express_chipset:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:q45_chipset:*:*:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00055
Низкий

7.2 High

CVSS2

Дефекты

CWE-16

Связанные уязвимости

github
почти 4 года назад

Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.

EPSS

Процентиль: 17%
0.00055
Низкий

7.2 High

CVSS2

Дефекты

CWE-16