CVE-2018-12209
Description
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to read device configuration information via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An insufficient access control flaw in the Intel Graphics Driver's User Mode Driver allows an unprivileged local user to read device configuration information.
Vulnerability
An insufficient access control vulnerability exists in the User Mode Driver (UMD) component of the Intel Graphics Driver for Windows. Versions before 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063), 21.20.x.5064 (aka 15.45.x.5064), and 24.20.100.6373 are affected. The driver fails to properly restrict access, allowing an unprivileged user to read device configuration information through local access [1].
Exploitation
An attacker must have local access to the system and the ability to interact with the vulnerable User Mode Driver interface. No administrative privileges or special authentication is required beyond being able to execute code or commands on the target machine. The attacker can trigger the vulnerable code path to query device configuration data, which the driver returns without adequate permission checks [1].
Impact
Successful exploitation leads to the disclosure of device configuration information. This is a confidentiality breach that could expose sensitive hardware details, which may aid in further targeted attacks. The attacker does not gain code execution or elevated privileges, but the information leak violates the intended access controls [1].
Mitigation
Intel released fixed driver versions that address the insufficient access control: 10.18.x.5059 (15.33.x.5059), 10.18.x.5057 (15.36.x.5057), 20.19.x.5063 (15.40.x.5063), 22.20.x.5064 (15.45.x.5064), and 24.20.100.6373. Users should update to these or later versions via the Intel Driver & Support Assistant or their system manufacturer's update channels [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: before 10.18.x.5059 (15.33.x.5059), 10.18.x.5057 (15.36.x.5057), 20.19.x.5063 (15.40.x.5063), 21.20.x.5064 (15.45.x.5064), and 24.20.100.6373
- Intel Corporation/Intel(R) Graphics Driver for Windowsv5Range: Multiple versions.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.lenovo.com/us/en/product_security/LEN-25084mitrex_refsource_CONFIRM
- www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00189.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.