[原文]Buffer overflow in Intel system Configuration utilities selview.exe and syscfg.exe before version 14 build 11 allows a local user to crash these services potentially resulting in a denial of service.



Intel System CU 14.0 / 14.1 Buffer Overflow (PacketStormID:F148496)
2018-07-11 00:00:00

Intel System CU versions 14.0 and 14.1 suffer from a buffer overflow vulnerability.

Technical Details & Description:
A local buffer overflow vulnerability has been discovered in the
official Intel System CU 14.0 and 14.1 utilities.
The vulnerability can be exploited by local attackers to overwrite
active registers to compromise the process or
affected computer system.

Intel system configuration utilities are vulnerable to a denial of
service, caused by a classic buffer overflow.
By sending a specially-crafted request, a local authenticated attacker
could exploit this vulnerability to cause
a denial of service condition.

Affected are versions of syscfg.exe before release 14.0 build 16 or for
systems based on IntelA(r) C620 Series
Chipsets 14.1 build 19. Affected are Versions of selview.exe before
release 14.0 build 21 or for systems based
on IntelA(r) C620 Series Chipsets before 14.0 build 11.

Exploitation of the local buffer overflow vulnerability requires no user
interaction and system process privileges.
Successful exploitation of the buffer overflow vulnerability results in
a compromise of the local system process or
affected computer system.

Vulnerable File(s):
[+] syscfg.exe
[+] selview.exe

Security Risk:
The security risk of the exploitable local buffer overflow vulnerability
in the utilities software is estimated as medium.

