CVE-2018-3649
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
10/05/2018
Last modified:
24/08/2020
Description
DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:intel:dual_band_wireless-ac_3160:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-ac_3160:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:dual_band_wireless-ac_7260:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-ac_7260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:dual_band_wireless-n_7260:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-n_7260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:wireless-n_7260:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:wireless-n_7260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:dual_band_wireless-ac_7260:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-ac_7260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:dual_band_wireless-ac_7265:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-ac_7265:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:dual_band_wireless-n_7265:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) | |
| cpe:2.3:h:intel:dual_band_wireless-n_7265:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:intel:wireless-n_7265:*:*:*:*:*:*:*:* | 20.20.2.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



