Intel Critical Privilege Escalation Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Successful exploitation can result in an attacker gaining complete control of a vulnerable system. The vulnerability can be exploited remotely, however the limiting factor of access to the required ports (TCP 16992 and 16993) restricts the likelihood of a remote attack and is more likely to be in used as an aid for lateral movement in a compromised network.
With access to a vulnerable system, an attacker is able to access an array of functionality including the KVM function that gives a user hardware level control over the keyboard and mouse. Code can be loaded remotely, files can be read and written to, boot priority can be modified to launch malicious boot images and more. Due to the intended purpose of the functionality, an attacker gains full control of all system administrator functionality on the target system.
For further information:
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 11:32 am