CVE-2019-0155 describes an insufficient access control vulnerability in Intel processor graphics subsystems affecting various Intel Core, Pentium, Celeron, Atom, and Xeon processor families, as well as Intel Graphics Drivers for Windows and the i915 Linux Driver. This flaw allows an authenticated local user to potentially achieve escalation of privilege. With a CVSS score of 7.8 (High), this vulnerability has a local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:* | ||
7.5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2:*:*:*:*:*:*:* | ||
< 26.20.100.6813CPE matchmatch criteria | cpe:2.3:a:intel:graphics_driver:*:*:*:*:*:windows:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:core_i9-10980xe_firmware:-:*:*:*:extreme:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.