Back to Database
Status published
High
CVE-2016-1493
Intel Driver Update Utility before 2.4 retrieves driver updates in...
Vulnerability Description
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-1493
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/135314/Intel-Driver-Update-Utility-2.2.0.5-Man-In-The-Middle.html
- http://www.coresecurity.com/advisories/intel-driver-update-utility-mitm
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00048&languageid=en-fr
- http://www.securityfocus.com/archive/1/537327/100/0/threaded
- http://seclists.org/fulldisclosure/2016/Jan/56
More from intel
View All →CVE-2022-32293
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR...
High
8.1
CVE-2022-32292
In ConnMan through 1.41, remote attackers able to send HTTP...
Critical
9.8
CVE-2022-23098
An issue was discovered in the DNS proxy in Connman...
High
7.5
CVE-2022-23097
An issue was discovered in the DNS proxy in Connman...
Critical
9.1
CVE-2022-23096
An issue was discovered in the DNS proxy in Connman...
Unknown
0
Affected Vendor
intel
View all reports →Affected Software
driver update utility
Vulnerable Versions:
2.0, 2.1, 2.2, 2.3
Timeline
Official Publish:
January 29th, 2016
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.