Vulnerability Description
DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Dual Band Wireless-Ac 3160 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 7260 | < 20.20.2.2 |
| Intel | Dual Band Wireless-N 7260 | < 20.20.2.2 |
| Intel | Wireless-N 7260 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 7265 | < 20.20.2.2 |
| Intel | Dual Band Wireless-N 7265 | < 20.20.2.2 |
| Intel | Wireless-N 7265 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 3165 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 3168 | < 20.20.2.2 |
| Intel | Tri-Band Wireless-Ac 17265 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 8260 | < 20.20.2.2 |
| Intel | Tri-Band Wireless-Ac 18260 | < 20.20.2.2 |
| Intel | Dual Band Wireless-Ac 8265 | < 20.20.2.2 |
| Intel | Tri-Band Wireless-Ac 18265 | < 20.20.2.2 |
| Intel | Wireless-Ac 9260 | < 20.20.2.2 |
| Intel | Wireless-Ac 9560 | < 20.20.2.2 |
| Intel | Wireless-Ac 9461 | < 20.20.2.2 |
| Intel | Wireless-Ac 9462 | < 20.20.2.2 |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00126.Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00126.Vendor Advisory
FAQ
What is CVE-2018-3649?
CVE-2018-3649 is a vulnerability with a CVSS score of 7.8 (HIGH). DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wirel...
How severe is CVE-2018-3649?
CVE-2018-3649 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3649?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Dual Band Wireless-Ac 3160, Intel Dual Band Wireless-Ac 7260, Intel Dual Band Wireless-N 7260, Intel Wireless-N 7260, Intel Dual Band Wireless-Ac 7265.