VYPR
Unrated severityNVD Advisory· Published Feb 18, 2019· Updated Sep 16, 2024

CVE-2019-0105

CVE-2019-0105

Description

Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In Intel Data Center Manager SDK before 5.0.2, insufficient permission checks in the installer allow a local authenticated user to escalate privileges.

Vulnerability

CVE-2019-0105 is a permission issue (CWE-275) in the install routine of the Intel Data Center Manager SDK [1][2]. Affected versions are prior to 5.0.2 [1][2]. The installer fails to properly verify file permissions, enabling a local authenticated user to modify or replace files during installation, leading to privilege escalation.

Exploitation

An attacker must have local access to the system and be authenticated as a user [1][2]. The attack complexity is high, requiring precise timing or conditions during the install process [2]. The attacker must run a malicious process that intercepts or modifies the installer's file operations, for example by placing a crafted file in a location the installer trusts with insufficient permission checking.

Impact

Successful exploitation allows the attacker to escalate privileges, potentially gaining administrative or SYSTEM-level access on the affected system [1][2]. This could lead to full compromise of the host, including data modification, denial of service, or further propagation [2].

Mitigation

Intel released version 5.0.2 of the Data Center Manager SDK to address this vulnerability [1][2]. Users should update to 5.0.2 or later. No workarounds have been published. The CVE is not listed on the CISA Known Exploited Vulnerabilities Catalog [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.