First published: Tue Mar 12 2019(Updated: )
Multiple out of bounds read in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Graphics Driver for Windows | =15.33.43.4425 | |
Intel Graphics Driver for Windows | =15.33.45.4653 | |
Intel Graphics Driver for Windows | =15.33.46.4885 | |
Intel Graphics Driver for Windows | =15.36.26.4294 | |
Intel Graphics Driver for Windows | =15.36.28.4332 | |
Intel Graphics Driver for Windows | =15.36.31.4414 | |
Intel Graphics Driver for Windows | =15.36.33.4578 | |
Intel Graphics Driver for Windows | =15.36.34.4889 | |
Intel Graphics Driver for Windows | =15.40.34.4624 | |
Intel Graphics Driver for Windows | =15.40.36.4703 | |
Intel Graphics Driver for Windows | =15.40.37.4835 | |
Intel Graphics Driver for Windows | =15.40.38.4963 | |
Intel Graphics Driver for Windows | =15.40.41.5058 | |
Intel Graphics Driver for Windows | =15.45.18.4664 | |
Intel Graphics Driver for Windows | =15.45.19.4678 | |
Intel Graphics Driver for Windows | =15.45.21.4821 | |
Intel Graphics Driver for Windows | =15.45.23.4860 | |
Intel Graphics Driver for Windows | =24.20.100.6025 | |
Intel Graphics Driver for Windows | =24.20.100.6094 | |
Intel Graphics Driver for Windows | =24.20.100.6136 | |
Intel Graphics Driver for Windows | =24.20.100.6194 | |
Intel Graphics Driver for Windows | =24.20.100.6229 | |
Intel Graphics Driver for Windows | =24.20.100.6286 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18089 is rated as a high severity vulnerability due to its potential to allow authenticated users to read out-of-bounds memory.
To fix CVE-2018-18089, update the Intel Graphics Driver to a version that is 10.18.x.5059 or later.
CVE-2018-18089 affects multiple versions of Intel Graphics Driver prior to versions 10.18.x.5059, 10.18.x.5057, 20.19.x.5063, 21.20.x.5064, and 24.20.100.6373.
An out-of-bounds read vulnerability like CVE-2018-18089 allows attackers to read memory areas that should not be accessible, potentially leading to information disclosure.
Any user with an authenticated session on a system running the affected versions of the Intel Graphics Driver is vulnerable to CVE-2018-18089.