Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-4419

18
FAUCET Score

CVE-2009-4419 affects several Intel chipsets (Q35, GM45, PM45 Express, Q45, and Q43 Express) within their SINIT Authenticated Code Module. This vulnerability allows a local attacker to bypass the Trusted Execution Technology protection mechanism and gain privileges. By modifying the MCHBAR register, an attacker can prevent the SENTER instruction from properly applying VT-d protection during an MLE load. The vulnerability has a CVSS score of 7.2, indicating high severity with local access, low attack complexity, and complete impact on confidentiality, integrity, and availability. Its FAUCET Risk Score is 45/100. There is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of older vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:intel:gm45_chipset:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:intel:pm45_express_chipset:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:intel:q35_chipset:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:intel:q43_express_chipset:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:h:intel:q45_chipset:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 51st percentile among its peer group of 3,237 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

invisiblethingslab.com / resources/misc09/Another%20TXT%20Attack.pdf
osvdb.org / 61248
secunia.com / advisories/37900
Vendor Advisory
security-center.intel.com / advisory.aspx
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/54963
theinvisiblethings.blogspot.com / 2009/12/another-txt-attack.html
securityfocus.com / bid/37430
securitytracker.com / id
vupen.com / english/advisories/2009/3618
Vendor Advisory