CVE-2019-14615
high-risk
Published 2020-01-17
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
Do I need to act?
~
4.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Products (20)
Atom E3805
Atom E3815
Atom E3825
Atom E3826
Atom E3827
Atom E3845
Atom E620
Atom E620T
Atom E640
Atom E640T
Atom E660
Atom E660T
Atom E680
Atom E680T
Atom X3-C3130
Atom X3-C3200Rk
References (38)
Third Party Advisory
http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LS...
Third Party Advisory
https://usn.ubuntu.com/4253-1/
Third Party Advisory
https://usn.ubuntu.com/4253-2/
Third Party Advisory
https://usn.ubuntu.com/4254-1/
Third Party Advisory
https://usn.ubuntu.com/4254-2/
Third Party Advisory
https://usn.ubuntu.com/4255-1/
Third Party Advisory
https://usn.ubuntu.com/4255-2/
and 18 more references
59
/ 100
high-risk
Severity
18/34 · Moderate
Exploitability
8/34 · Low
Exposure
33/34 · Critical