« Volver al listado

CVE-2018-18094

Estado: ModificadaAlta (7.8)—

Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-18094",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Intel(R) Media SDK Advisory",
          "versions": [
            {
              "status": "affected",
              "version": "Versions before 2018 R2.1."
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-17T18:29:00.217",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/107886",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00201.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/107886",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00201.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation of privilege via local access."
    },
    {
      "lang": "es",
      "value": "Los permisos de directorio incorrectos en el instalador para Intel (R) Media SDK versión anterior a 2018 R 2.1 permiten que un usuario autorizado habilite potencialmente la escalada de privilegios por medio  del acceso local."
    }
  ],
  "lastModified": "2026-06-17T01:46:46.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:intel:media_sdk:2017:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FB0F241-E6E1-44E6-BDF7-8EC2F14388C0"
            },
            {
              "criteria": "cpe:2.3:a:intel:media_sdk:2017:r2.1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B9DABC8-B52A-4636-B976-43928ED85377"
            },
            {
              "criteria": "cpe:2.3:a:intel:media_sdk:2018:r1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75FDDBB8-0EB5-4757-932B-49AED0F3A944"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}