CVE-2016-5647
Last modified
CVE-2016-5647 is a vulnerability of currently unknown severity. The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Graphics Driver | >= 15.33, <= 15.33.42.4358 |
| Intel | Graphics Driver | >= 15.36, <= 15.36.30.4385 |
| Intel | Graphics Driver | >= 15.40, <= 15.40.4404 |
References
- http://www.securityfocus.com/bid/91708Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0087/Exploit, Third Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00054&languageid=en-frPatch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/ps500068Third Party Advisory
- http://www.securityfocus.com/bid/91708Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0087/Exploit, Third Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00054&languageid=en-frPatch, Vendor Advisory
- https://support.lenovo.com/us/en/product_security/ps500068Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5647?
How severe is CVE-2016-5647?
How do I fix CVE-2016-5647?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-5638There are few web pages associated with the genie app on the…
- CVE-2016-5639Directory traversal vulnerability in cgi-bin/login.cgi on Cr…
- CVE-2016-5640Directory traversal vulnerability in cgi-bin/rftest.cgi on C…
- CVE-2016-5642Opmantek NMIS before 8.5.12G has XSS via SNMP.
- CVE-2016-5645Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L3…7.3
- CVE-2016-5646An exploitable heap overflow vulnerability exists in the Com…
- CVE-2016-5648Acer Portal app before 3.9.4.2000 for Android does not prope…
- CVE-2016-5649A vulnerability is in the 'BSW_cxttongr.htm' page of the Net…
- CVE-2016-5650ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2…
- CVE-2016-5652An exploitable heap-based buffer overflow exists in the hand…
- CVE-2016-5653Multiple SQL injection vulnerabilities in Misys FusionCapita…
- CVE-2016-5654Misys FusionCapital Opics Plus allows remote authenticated u…
Are you affected by CVE-2016-5647?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
