CVE-2018-3649

moderate-risk
Published 2018-05-10

DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.

Do I need to act?

-
0.16% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10 High
LOCAL / LOW complexity

Affected Products (18)

Dual Band Wireless-Ac 3160
Dual Band Wireless-Ac 7260
Dual Band Wireless-N 7260
Wireless-N 7260
Dual Band Wireless-Ac 7265
Dual Band Wireless-N 7265
Wireless-N 7265
Dual Band Wireless-Ac 3165
Dual Band Wireless-Ac 3168
Tri-Band Wireless-Ac 17265
Dual Band Wireless-Ac 8260
Tri-Band Wireless-Ac 18260
Dual Band Wireless-Ac 8265
Tri-Band Wireless-Ac 18265
Wireless-Ac 9260
Wireless-Ac 9560
Wireless-Ac 9461
Wireless-Ac 9462

Affected Vendors

44
/ 100
moderate-risk
Severity 24/34 · High
Exploitability 1/34 · Minimal
Exposure 19/34 · Moderate