CVE-2015-2291

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Aug 9, 2017
Updated: Aug 24, 2017
CWE ID 20

Summary

CVE-2015-2291 is a vulnerability affecting the Intel Ethernet diagnostics driver for Windows before version 1.3.1.0. maliciously crafted IOCTL calls, specifically 0x80862013, 0x8086200B, 0x8086200F, and 0x80862007, can be exploited by local users to cause a denial of service or potentially execute arbitrary code with kernel privileges. This issue poses a significant risk to the affected systems and requires immediate patching to mitigate it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share