CVE-2006-6385
Summary
| CVE | CVE-2006-6385 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-08 01:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in Intel PRO 10/100, PRO/1000, and PRO/10GbE PCI, PCI-X, and PCIe network adapter drivers (aka NDIS miniport drivers) before 20061205 allows local users to execute arbitrary code with "kernel-level" privileges via an incorrect function call in certain OID handlers. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Intel | Pro 1000 Adapters | All | All | All | All |
| Hardware | Intel | Pro 1000 Adapters | All | All | All | All |
| Hardware | Intel | Pro 1000 Adapters | All | All | All | All |
| Hardware | Intel | Pro 1000 Pcie Adapters | All | All | All | All |
| Hardware | Intel | Pro 10gbe Adapters | All | All | All | All |
| Hardware | Intel | Pro 10 100 Adapters | All | All | All | All |
| Hardware | Intel | Pro 10 100 Adapters | All | All | All | All |
| Hardware | Intel | Pro 10 100 Adapters | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Intel Support | af854a3a-2127-422b-91ae-364da2661108 | www.intel.com | Patch |
| Intel Network Drivers Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| eEye Digital Security - Research | af854a3a-2127-422b-91ae-364da2661108 | research.eeye.com | |
| US-CERT Vulnerability Note VU#296681 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| eEye Digital Security - Research | af854a3a-2127-422b-91ae-364da2661108 | research.eeye.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - Intel LAN Driver Buffer Overflow Lets Local Users Obtain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Intel LAN Driver Buffer Overflow Local Privilege Escalation | af854a3a-2127-422b-91ae-364da2661108 | lists.freebsd.org | |
| This page provides Security Information. : FUJITSU | af854a3a-2127-422b-91ae-364da2661108 | www.fujitsu.com | |
| Intel LAN Driver OID Handler Privilege Escalation Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason - Intel Network Adapter Driver Local Privilege Escalation | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-12-08 | Joshua Bressers | Not Vulnerable. eEye Research advisory AD20061207 (Intel Network Adapter Driver Local Privilege Escalation) describes a flaw in the Linux Kernel drivers for the e100, e1000, and ixgb Intel network cards. The flaw affects the NDIS miniport drivers and its OID support. The Linux Kernel drivers do not support the NDIS API and the OID concept from Microsoft Windows. |
There are currently no legacy QID mappings associated with this CVE.