HIGH · 7.2

CVE-2009-4419

Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and ...

Vulnerability Description

Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
IntelGm45 ChipsetAll versions
IntelPm45 Express ChipsetAll versions
IntelQ35 ChipsetAll versions
IntelQ43 Express ChipsetAll versions
IntelQ45 ChipsetAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-4419?

CVE-2009-4419 is a vulnerability with a CVSS score of 7.2 (HIGH). Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and ...

How severe is CVE-2009-4419?

CVE-2009-4419 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-4419?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Gm45 Chipset, Intel Pm45 Express Chipset, Intel Q35 Chipset, Intel Q43 Express Chipset, Intel Q45 Chipset.