CVE-2016-1493

HIGH

Intel Driver Update Utility <2.4 - RCE

Title source: llm
STIX 2.1

Description

Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537327/100/0/threaded
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Jan/56

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (4)
intel/driver_update_utility 2.0
intel/driver_update_utility 2.1
intel/driver_update_utility 2.2
intel/driver_update_utility 2.3
Published Jan 29, 2016
Tracked Since Feb 18, 2026