CVE-2019-0155

HIGHCVSS 7.8/10EPSS 0.67%

Last modified

CVE-2019-0155 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.

Description

Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.67%

47.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Eus7.5
RedhatEnterprise Linux Server Tus7.2
IntelGraphics Driver< 26.20.100.6813
IntelCore I9-10980xe FirmwareAll versions
IntelCore I9-10900x FirmwareAll versions
IntelCore I9-10920x FirmwareAll versions
IntelCore I9-9900x FirmwareAll versions
IntelCore I9-9920x FirmwareAll versions
IntelCore I9-9960x FirmwareAll versions
IntelCore I9-9980xe FirmwareAll versions
IntelCore I9-9940x FirmwareAll versions
IntelCore I9-7960x FirmwareAll versions
IntelCore I9-7940x FirmwareAll versions
IntelCore I9-7980xe FirmwareAll versions
IntelCore I9-7920x FirmwareAll versions
IntelCore I9-7900x FirmwareAll versions
IntelCore I7-7820x FirmwareAll versions
IntelCore I7-7800x FirmwareAll versions
IntelCore I9-9900ks FirmwareAll versions
IntelCore I9-9900t FirmwareAll versions
IntelCore I9-9900 FirmwareAll versions
IntelCore I9-9880h FirmwareAll versions
IntelCore I9-9980hk FirmwareAll versions
IntelCore I9-9900k FirmwareAll versions
IntelCore I9-8950hk FirmwareAll versions
IntelCore I7-10510u FirmwareAll versions
IntelCore I7-10510y FirmwareAll versions
IntelCore I7-10710u FirmwareAll versions
IntelCore I7-1065g7 FirmwareAll versions
IntelCore I7-9700t FirmwareAll versions
IntelCore I7-9700 FirmwareAll versions
IntelCore I7-9750h FirmwareAll versions
IntelCore I7-9850h FirmwareAll versions
IntelCore I7-9700k FirmwareAll versions
IntelCore I7-8565u FirmwareAll versions
IntelCore I7-8500y FirmwareAll versions
IntelCore I7-8086k FirmwareAll versions
IntelCore I7-8750h FirmwareAll versions
IntelCore I7-8559u FirmwareAll versions
IntelCore I7\+8700 FirmwareAll versions
IntelCore I7-8709g FirmwareAll versions
IntelCore I7-8809g FirmwareAll versions
IntelCore I7-8705g FirmwareAll versions
IntelCore I7-8706g FirmwareAll versions
IntelCore I7-8550u FirmwareAll versions
IntelCore I7-8650u FirmwareAll versions
IntelCore I7-7700t FirmwareAll versions
IntelCore I7-7820hk FirmwareAll versions
IntelCore I7-7700hq FirmwareAll versions

Showing 50 of 363 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-0155?
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privilege via local access.
How severe is CVE-2019-0155?
CVE-2019-0155 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.67% probability of exploitation in the next 30 days.
How do I fix CVE-2019-0155?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-0155?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST