CVE-2019-14615

MEDIUMCVSS 5.5/10EPSS 1.45%

Last modified

CVE-2019-14615 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.

Description

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Probability
1.45%

70.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux19.10
IntelAtom E3805All versions
IntelAtom E3815All versions
IntelAtom E3825All versions
IntelAtom E3826All versions
IntelAtom E3827All versions
IntelAtom E3845All versions
IntelAtom E620All versions
IntelAtom E620tAll versions
IntelAtom E640All versions
IntelAtom E640tAll versions
IntelAtom E660All versions
IntelAtom E660tAll versions
IntelAtom E680All versions
IntelAtom E680tAll versions
IntelAtom X3-C3130All versions
IntelAtom X3-C3200rkAll versions
IntelAtom X3-C3230rkAll versions
IntelAtom X3-C3405All versions
IntelAtom X3-C3445All versions
IntelAtom X5-Z8300All versions
IntelAtom X5-Z8330All versions
IntelAtom X5-Z8500All versions
IntelAtom X7-Z8700All versions
IntelAtom Z2420All versions
IntelAtom Z2460All versions
IntelAtom Z2480All versions
IntelAtom Z2520All versions
IntelAtom Z2560All versions
IntelAtom Z2580All versions
IntelAtom Z2760All versions
IntelAtom Z3460All versions
IntelAtom Z3480All versions
IntelAtom Z3530All versions
IntelAtom Z3560All versions
IntelAtom Z3570All versions
IntelAtom Z3580All versions
IntelAtom Z3590All versions
IntelAtom Z3735dAll versions
IntelAtom Z3735eAll versions
IntelAtom Z3735fAll versions
IntelAtom Z3735gAll versions
IntelAtom Z3736fAll versions
IntelAtom Z3736gAll versions
IntelAtom Z3740All versions
IntelAtom Z3740dAll versions
IntelAtom Z3745All versions

Showing 50 of 482 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-14615?
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
How severe is CVE-2019-14615?
CVE-2019-14615 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 1.45% probability of exploitation in the next 30 days.
How do I fix CVE-2019-14615?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-14615?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST