CVE-2009-4419
Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- intel/gm45 chipset · intel/pm45 express chipset · intel/q35 chipset · intel/q43 express chipset · intel/q45 chipset
- Source
- cve@mitre.org
References
- http://invisiblethingslab.com/resources/misc09/Another%20TXT%20Attack.pdf
- http://osvdb.org/61248
- http://secunia.com/advisories/37900Vendor Advisory
- http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00021&languageid=en-frVendor Advisory
- http://theinvisiblethings.blogspot.com/2009/12/another-txt-attack.html
- http://www.securityfocus.com/bid/37430
- http://www.securitytracker.com/id?1023382
- http://www.vupen.com/english/advisories/2009/3618Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54963
- http://invisiblethingslab.com/resources/misc09/Another%20TXT%20Attack.pdf
- http://osvdb.org/61248
- http://secunia.com/advisories/37900Vendor Advisory
- http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00021&languageid=en-frVendor Advisory
- http://theinvisiblethings.blogspot.com/2009/12/another-txt-attack.html
- http://www.securityfocus.com/bid/37430
- http://www.securitytracker.com/id?1023382
- http://www.vupen.com/english/advisories/2009/3618Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54963
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.