CVE-2019-1010066 Information
Feb 14, 2021
cve
Description
Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist checking in order to write to model specific registers normally a function reserved for the root user. The fixed version is: v1.2.0.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
https://github.com/LLNL/msr-safe/compare/v1.1.0…v1.2.0 https://www.tldp.org/LDP/lkmpg/2.4/html/x856.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.5
Share on: