CVE-2008-7096

Intel BIOS - Privilege Escalation via SMM Register Access

Title source: llm
STIX 2.1

Description

Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30823
Various Sources x_refsource_misc
http://invisiblethingslab.com/bh08/part2-full.pdf
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44676
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49901

Scores

EPSS 0.0006
EPSS Percentile 18.9%

Details

CWE
CWE-264
Status published
Products (8)
intel/bios dg33bu
intel/bios dg33fb
intel/bios dg33tl
intel/bios dp35dp
intel/bios dq35jo
intel/bios dq35mp
intel/bios dx38bt
intel/bios mgm965tw
Published Aug 27, 2009
Tracked Since Feb 18, 2026