ID

VAR-202003-0359


CVE

CVE-2020-0517


TITLE

Intel(R) Graphics Driver Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-002982

DESCRIPTION

Out-of-bounds write in Intel(R) Graphics Drivers before version 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access. Intel(R) Graphics Driver There is an unspecified vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Intel Graphics Drivers is an integrated graphics driver from Intel Corporation. A buffer error vulnerability exists in Intel Graphics Drivers prior to 15.36.38.5117. A local attacker could exploit this vulnerability to elevate privileges

Trust: 1.71

sources: NVD: CVE-2020-0517 // JVNDB: JVNDB-2020-002982 // VULHUB: VHN-161951

AFFECTED PRODUCTS

vendor:intelmodel:graphics driverscope:ltversion:15.36.38.5117

Trust: 1.0

vendor:intelmodel:graphics driverscope:eqversion:15.36.38.5117

Trust: 0.8

sources: JVNDB: JVNDB-2020-002982 // NVD: CVE-2020-0517

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-0517
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-002982
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202003-542
value: MEDIUM

Trust: 0.6

VULHUB: VHN-161951
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-0517
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-002982
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-161951
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-0517
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 1.8
impactScore: 3.4
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-002982
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-161951 // JVNDB: JVNDB-2020-002982 // CNNVD: CNNVD-202003-542 // NVD: CVE-2020-0517

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.1

sources: VULHUB: VHN-161951 // NVD: CVE-2020-0517

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202003-542

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202003-542

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-002982

PATCH

title:INTEL-SA-00315url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00315.html

Trust: 0.8

title:Intel Graphics Drivers Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=112007

Trust: 0.6

sources: JVNDB: JVNDB-2020-002982 // CNNVD: CNNVD-202003-542

EXTERNAL IDS

db:NVDid:CVE-2020-0517

Trust: 2.5

db:JVNid:JVNVU94445466

Trust: 0.8

db:JVNDBid:JVNDB-2020-002982

Trust: 0.8

db:CNNVDid:CNNVD-202003-542

Trust: 0.7

db:LENOVOid:LEN-30555

Trust: 0.6

db:AUSCERTid:ESB-2020.0871

Trust: 0.6

db:VULHUBid:VHN-161951

Trust: 0.1

sources: VULHUB: VHN-161951 // JVNDB: JVNDB-2020-002982 // CNNVD: CNNVD-202003-542 // NVD: CVE-2020-0517

REFERENCES

url:https://security.netapp.com/advisory/ntap-20200320-0003/

Trust: 1.7

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00315.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-0517

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-0517

Trust: 0.8

url:http://jvn.jp/vu/jvnvu94445466/index.html

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.0871/

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-30555

Trust: 0.6

sources: VULHUB: VHN-161951 // JVNDB: JVNDB-2020-002982 // CNNVD: CNNVD-202003-542 // NVD: CVE-2020-0517

CREDITS

RanchoIce of Tencent Security ZhanluLab

Trust: 0.6

sources: CNNVD: CNNVD-202003-542

SOURCES

db:VULHUBid:VHN-161951
db:JVNDBid:JVNDB-2020-002982
db:CNNVDid:CNNVD-202003-542
db:NVDid:CVE-2020-0517

LAST UPDATE DATE

2024-11-23T20:34:31.075000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-161951date:2022-01-01T00:00:00
db:JVNDBid:JVNDB-2020-002982date:2020-03-31T00:00:00
db:CNNVDid:CNNVD-202003-542date:2022-01-04T00:00:00
db:NVDid:CVE-2020-0517date:2024-11-21T04:53:39.283

SOURCES RELEASE DATE

db:VULHUBid:VHN-161951date:2020-03-12T00:00:00
db:JVNDBid:JVNDB-2020-002982date:2020-03-31T00:00:00
db:CNNVDid:CNNVD-202003-542date:2020-03-10T00:00:00
db:NVDid:CVE-2020-0517date:2020-03-12T20:15:12.800