Escalation of Privilege Vulnerability in Intel Ethernet 500 Series Controller Drivers for VMware
CVE-2022-36416

4.4MEDIUM

Key Information:

Vendor
Vmware
Vendor
CVE Published:
16 February 2023

Summary

A vulnerability exists in the Intel Ethernet 500 Series Controller drivers for VMware prior to version 1.10.0.13, resulting from a failure in protection mechanisms. This allows an authenticated user to potentially escalate privileges through local access, creating risks for unauthorized operations and access to sensitive data.

Affected Version(s)

Intel(R) Ethernet 500 Series Controller drivers for VMware before version 1.10.0.13

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.