Intel System Management Mode Local Privilege Escalation Vulnerability

BID:35861

Info

Intel System Management Mode Local Privilege Escalation Vulnerability

Bugtraq ID: 35861
Class: Unknown
CVE:
Remote: No
Local: Yes
Published: Jul 29 2009 12:00AM
Updated: Oct 05 2009 11:39PM
Credit: Alexander Tereshkin, Rafal Wojtczuk, and Joanna Rutkowska from Invisible Things Lab
Vulnerable: Intel S7000 Series 0
Intel S5500 Series 0
Intel S5400 Series 0
Intel S5000 Series 0
Intel S3200 Series 0
Intel S3000 Series 0
Intel DX58SO 0
Intel DX48BT2 0
Intel DX38BT 0
Intel DQ45EK 0
Intel DQ45CB 0
Intel DQ43AP 0
Intel DQ35MP 0
Intel DQ35JO 0
Intel DP45SG 0
Intel DP43TF 0
Intel DP35DP 0
Intel DG45ID 0
Intel DG45FC 0
Intel DG43NB 0
Intel DG41TY 0
Intel DG41RQ 0
Intel DG41MJ 0
Intel DG35EC 0
Intel DG33TL 0
Intel DG33FB 0
Intel DG33BU 0
Intel DB43LD 0
Intel D945GSEJT 0
Intel D945GSEJT 0
Intel D945GCLF2 0
Intel D945GCLF 0
Intel D5400XS 0
Not Vulnerable: Intel S7000 Series SFC4UR.86B.01.00.002
Intel S5500 Series S5500.86B.01.00.0037
Intel S5400 Series S5400.86B.06.00.0032
Intel S5000 Series S5000.86B.12.00.0098
Intel S3200 Series 3200X38.86B.00.00.00
Intel S3000 Series S3000.86B.02.00.0054
Intel DX58SO SOX5810J.86A.4196
Intel DX48BT2 BTX3810J.86A.2000
Intel DX38BT BTX3810J.86A.2000
Intel DQ45EK CBQ4510H.86A.0087
Intel DQ45CB CBQ4510H.86A.0087
Intel DQ43AP APQ4310H.86A.0025
Intel DQ35MP JOQ3510J.86A.1108
Intel DQ35JO JOQ3510J.86A.1108
Intel DP45SG SGP4510H.86A.0118
Intel DP43TF NBG4310H.86A.0087
Intel DP35DP DPP3510J.86A.0572
Intel DG45ID IDG4510H.86A.0105
Intel DG45FC IDG4510H.86A.0105
Intel DG43NB NBG4310H.86A.0087
Intel DG41TY TYG4110H.86A.0030
Intel DG41RQ RQG4110H.86A.0011
Intel DG41MJ MJG4110H.86A.0004
Intel DG33TL DPP3510J.86A.0572
Intel DG33FB DPP3510J.86A.0572
Intel DG33BU DPP3510J.86A.0572
Intel DB43LD LDB4310H.86A.0031
Intel D945GSEJT JT94510H.86A.0032
Intel D945GCLF2 LF94510J.86A.0183
Intel D945GCLF LF94510J.86A.0183
Intel D5400XS XS54010J.86A.1338

Discussion

Intel System Management Mode Local Privilege Escalation Vulnerability

Intel BIOS is prone to an unspecified privilege-escalation vulnerability.

Successfully exploiting this issue will allow programs running with administrative (ring 0) privileges to modify code running in System Management Mode.

Currently very few technical details are available. We will update this BID as more information emerges.

Exploit / POC

Intel System Management Mode Local Privilege Escalation Vulnerability

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Intel System Management Mode Local Privilege Escalation Vulnerability

Solution:
Intel has released fixes; please see the references for details.

References

Intel System Management Mode Local Privilege Escalation Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report