CVE-2018-3700

MEDIUM

Intel USB 3.0 eXtensible Host Controller Driver < 5.0.4.43v2 - Code Injection via Installer

Title source: llm
STIX 2.1

Description

Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v2 may allow a user to potentially enable escalation of privilege via local access.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107073

Scores

CVSS v3 6.7
EPSS 0.0014
EPSS Percentile 33.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
intel/usb_3.0_extensible_host_controller_driver < 5.0.4.43v2
Published Feb 18, 2019
Tracked Since Feb 18, 2026