Rewterz Threat Alert – “Stealc” – An Information Stealer Malware Found in Several Instances in the Wild – Active IOCs
February 27, 2023Rewterz Threat Advisory – Multiple Cisco Products Vulnerabilities
February 27, 2023Rewterz Threat Alert – “Stealc” – An Information Stealer Malware Found in Several Instances in the Wild – Active IOCs
February 27, 2023Rewterz Threat Advisory – Multiple Cisco Products Vulnerabilities
February 27, 2023Severity
Medium
Analysis Summary
CVE-2022-36382 CVSS:6
Intel X710 and E810 Series Ethernet Controllers and Adapters is vulnerable to a denial of service, caused by an out-of-bounds write in firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service.
CVE-2022-38056 CVSS:3.8
Intel Endpoint Management Assistant could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper neutralization of user-supplied input. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain elevated privileges.
CVE-2021-33104 CVSS:6.5
Intel One Boot Flash Utility (OFU) software is vulnerable to a denial of service, caused by improper access control. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service.
CVE-2022-36287 CVSS:4
Intel FCS Server software is vulnerable to a denial of service, caused by an uncaught exception. A physical attacker could exploit this vulnerability to cause a denial of service.
CVE-2022-36797 CVSS:3.3
Intel Ethernet 500 Series Controller drivers for VMware are vulnerable to a denial of service, caused by protection mechanism failure. A local authenticated attacker could exploit this vulnerability to cause a denial of service.
CVE-2022-36416 CVSS:4.4
Intel Ethernet 500 Series Controller drivers for VMware could allow a local authenticated attacker to gain elevated privileges on the system, caused by protection mechanism failure. An attacker could exploit this vulnerability to gain elevated privileges on the system.
CVE-2022-27808 CVSS:6.3
Intel Ethernet Controller Administrative Tools drivers for Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by insufficient control flow management. An attacker could exploit this vulnerability to gain elevated privileges on the system.
CVE-2022-27234 CVSS:4.3
Intel Computer Vision Annotation Tool is vulnerable to server-side request forgery. A remote authenticated attacker could exploit this vulnerability to conduct an SSRF attack, allowing the attacker to obtain sensitive information.
CVE-2022-38090 CVSS:6
Intel processors could allow a local authenticated attacker to obtain sensitive information, caused by improper isolation of shared resources. An attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
CVE-2022-41314 CVSS:6.7
Intel Network Adapter software could allow a local authenticated attacker to gain elevated privileges on the system, caused by an uncontrolled search path element. An attacker could exploit this vulnerability to gain elevated privileges on the system.
Impact
- Privilege Escalation
- Denial of Service
- Information Disclosure
- Unauthorized Access
Indicators Of Compromise
CVE
- CVE-2022-36382
- CVE-2022-38056
- CVE-2021-33104
- CVE-2022-36287
- CVE-2022-36797
- CVE-2022-36416
- CVE-2022-27808
- CVE-2022-27234
- CVE-2022-38090
- CVE-2022-41314
Affected Vendors
Intel
Affected Products
- Intel E810 Series Ethernet Network Controllers and Adapters 1.7.0.7
- Intel X710 Series Ethernet Network Controllers and Adapters 9.100
- Intel Endpoint Management Assistant 1.3.1
- Intel Endpoint Management Assistant 1.3.2
- Intel Endpoint Management Assistant 1.7.1
- Intel Endpoint Management Assistant 1.8.0
- Intel One Boot Flash Utility 14.1.22
- Intel One Boot Flash Utility 14.1.24
- Intel One Boot Flash Utility 14.1.26
- Intel FCS Server software 1.1.79.1
- Intel FCS Server software 1.1.79.2
- Intel Ethernet 500 Series Controller drivers for VMware 1.10.0.0
- Intel Ethernet 500 Series Controller drivers for VMware 1.9.9.9
- Intel Ethernet Controller Administrative Tools drivers for Windows 1.5.0.0
- Intel Ethernet Controller Administrative Tools drivers for Windows 1.5.0.1
- Intel Computer Vision Annotation Tool 1.9.9
- Intel Computer Vision Annotation Tool 2.0.0
- Intel 10th Generation Intel Core Processor Family
- Intel 3rd Generation Intel Xeon Scalable Processor Family
- Intel 9th Generation Intel Core Processor Family
- Intel Celeron Processor J Series
- Intel Celeron processor N series
- Intel Pentium Silver Processor Series
- Intel Xeon D Processors
- Intel Administrative Tools for Intel Network Adapters 27.2
- Intel Non-Volatile Memory (NVM) Update Utility for Intel Ethernet Network Adapter E810 Series 4.00
Remediation
Refer to Intel Security Advisory for patch, upgrade or suggested workaround information.