CVE-2018-18094

HIGH

Intel Media SDK - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107886

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
intel/media_sdk 2017 (2 CPE variants)
intel/media_sdk 2018 r1
Published Apr 17, 2019
Tracked Since Feb 18, 2026