QID 374285

Date Published: 2021-05-05

QID 374285: Intel Wireless Bluetooth Driver Privilege Escalation Vulnerability

Bluetooth Technology is a wireless technology that enables short-range wireless communication between electronics devices.

CVE-2020-12321: Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2020-12322: Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Affected Product:
Intel Wi-Fi 6 AX201 Intel Wi-Fi 6 AX200 Intel Wireless-AC 9560 Intel Wireless-AC 9462 Intel Wireless-AC 9461 Intel Wireless-AC 9260 Intel Dual Band Wireless-AC 8265 Intel Dual Band Wireless-AC 8260 Intel Dual Band Wireless-AC 3168 Intel Wireless 7265 (Rev D) Family Intel Dual Band Wireless-AC 3165 QID detection logic: (Authenticated)
This QID checks Windows Registry to enumerate all the Network Adapters to verify the DriverDescription and DriverVersion to see if it's running a vulnerable version.

Successful exploitation of the vulnerability may allow an attacker to perform denial of service and escalation of privilege attack.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to INTEL-SA-00403 for software updates and further details.

    CVEs related to QID 374285

    Software Advisories
    Advisory ID Software Component Link
    INTEL-SA-00403 WIndows URL Logo www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00403.html