CVE-2019-11113
Last modified
CVE-2019-11113 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5077) may allow a privileged user to potentially enable information disclosure via local access.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5077) may allow a privileged user to potentially enable information disclosure via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Graphics Driver | < 25.20.100.6618 |
| Intel | Graphics Driver | 15.22.54.64.2622 |
| Intel | Graphics Driver | 15.22.54.2622 |
| Intel | Graphics Driver | 15.22.58.64.2993 |
| Intel | Graphics Driver | 15.22.58.2993 |
| Intel | Graphics Driver | 15.28.24.64.4229 |
| Intel | Graphics Driver | 15.28.24.4229 |
| Intel | Graphics Driver | 15.33.48.5069 |
| Intel | Graphics Driver | 15.36.36.5067 |
| Intel | Graphics Driver | 15.36.37.5074 |
| Intel | Graphics Driver | 15.40.1.64.4256 |
| Intel | Graphics Driver | 15.40.7.64.4279 |
| Intel | Graphics Driver | 15.40.14.4352 |
| Intel | Graphics Driver | 15.40.26.4474 |
| Intel | Graphics Driver | 15.40.42.5063 |
| Intel | Graphics Driver | 15.45.26.5065 |
| Intel | Graphics Driver | 15.45.27.5068 |
| Intel | Graphics Driver | 15.45.29.5077 |
| Netapp | Cloud Backup | All versions |
| Netapp | Data Availability Services | All versions |
| Netapp | Steelstore Cloud Integrated Storage | All versions |
| Netapp | Solidfire Baseboard Management Controller Firmware | All versions |
References
- https://security.netapp.com/advisory/ntap-20200320-0005/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200320-0005/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11113?
How severe is CVE-2019-11113?
How do I fix CVE-2019-11113?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11108Insufficient input validation in subsystem for Intel(R) CSME…6.7
- CVE-2019-11109Logic issue in the subsystem for Intel(R) SPS before version…4.4
- CVE-2019-1111A remote code execution vulnerability exists in Microsoft Ex…
- CVE-2019-11110Authentication bypass in the subsystem for Intel(R) CSME bef…6.7
- CVE-2019-11111Pointer corruption in the Unified Shader Compiler in Intel(R…7.8
- CVE-2019-11112Memory corruption in Kernel Mode Driver in Intel(R) Graphics…7.8
- CVE-2019-11114Insufficient input validation in Intel(R) Driver & Support A…
- CVE-2019-11115Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-11116Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-11117Improper permissions in the installer for Intel(R) Omni-Path…7.8
- CVE-2019-11118Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-11119Insufficient session validation in the service API for Intel…9.8
Are you affected by CVE-2019-11113?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
