CVE-2009-4419 affects several Intel chipsets (Q35, GM45, PM45 Express, Q45, and Q43 Express) within their SINIT Authenticated Code Module. This vulnerability allows a local attacker to bypass the Trusted Execution Technology protection mechanism and gain privileges. By modifying the MCHBAR register, an attacker can prevent the SENTER instruction from properly applying VT-d protection during an MLE load. The vulnerability has a CVSS score of 7.2, indicating high severity with local access, low attack complexity, and complete impact on confidentiality, integrity, and availability. Its FAUCET Risk Score is 45/100. There is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of older vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:intel:gm45_chipset:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:intel:pm45_express_chipset:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:intel:q35_chipset:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:intel:q43_express_chipset:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:intel:q45_chipset:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.