CVE-2018-12131: High severity intel client nvme vulnerability
Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticated user to potentially escalate privilege via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-12131?
CVE-2018-12131 is a vulnerability that allows an authenticated user to potentially escalate privilege via local access in Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083.
What is the severity of CVE-2018-12131?
CVE-2018-12131 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2018-12131?
Intel Client Nvme with versions up to (exclusive) 4.0.0.1007, Intel Datacenter Nvme with versions up to (inclusive) 4.0.0.1006, and Intel Rapid Storage Technology with versions up to (exclusive) 4.7.0.2083 are affected by CVE-2018-12131.
How can an authenticated user potentially exploit CVE-2018-12131?
An authenticated user could potentially escalate privilege via local access using the vulnerabilities in Intel NVMe and Intel RSTe.
Where can I find more information about CVE-2018-12131?
More information about CVE-2018-12131 can be found at the following link: [Intel Security Center Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00154.html)