CVE-2019-11163 describes an insufficient access control vulnerability in a hardware abstraction driver within the Intel Processor Identification Utility for Windows, affecting versions prior to 6.1.0731. This flaw allows an authenticated local user to potentially achieve escalation of privilege, denial of service, or information disclosure. With a CVSS score of 7.8 (HIGH), it is easily exploitable locally with low attack complexity and no user interaction, leading to high impact across confidentiality, integrity, and availability. While not listed in CISA KEV and lacking public exploit code on Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.0731CPE matchmatch criteria | cpe:2.3:a:intel:processor_identification_utility:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.