-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2020.0013
               Intel SNMP Subagent advisory (INTEL-SA-00300)
                              15 January 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Intel SNMP Subagent Stand-Alone
Operating System:     Windows
Impact/Access:        Increased Privileges -- Existing Account
Resolution:           None
CVE Names:            CVE-2019-14600  
Member content until: Friday, February 14 2020

OVERVIEW

        Intel is discontinuing the Intel SNMP Subagent Stand-Alone software
        due to a privilege escalation vulnerability. [1]


IMPACT

        "CVEID: CVE-2019-14600
        
        Description: Uncontrolled search path element in the installer for Intel(R)
        SNMP Subagent Stand-Alone for Windows may allow an authenticated user to
        potentially enable escalation of privilege via local access.
        
        CVSS Base Score: 6.5 Medium
        
        CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" [1]


MITIGATION

        Intel recommends uninstalling or discontinuing use of the software. [1]


REFERENCES

        [1] Intel SNMP Subagent Stand-Alone Advisory for Windows
            https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00300.html

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXh6JBGaOgq3Tt24GAQjOtQ/9HgZdiYdDrWg5dhFVOxd4DORSjdpnA6OF
lwO1pwAh7VcUaJ/cPZFqE2Ac6rbGfrMGcal7CMazAegMIx/lrupMGBzV7U3pCJgq
kz2/0pTjBU8Gp0C8fm2/egnjhvgppgbiokWJH0wtieYXtCqHPlMfA0E1oFqwnXSD
0DBjGYCAnjbRZxZ60D2q1juuSLTCiGzPcdiaI5+eMoi2GppiYS38w/z1nJ8zf9xR
oNYgzfsEP1F4nTRUNGHdM3nx15ASAP293pi+hT8RE7fmJwSBgv9NTfAjSFcJ2Z/Y
qydIRum3zv3V0yOcUgIMQKuH2ujC/XtGA+Hvy2Vk0UAylAMWNutdnvMvcQ1r4PVO
F6gE5Iq+7h4lsuPvjMgDtfnHpGvEHF5NtrkXfGlrS1qLvdWseGVwOGaEcqRh8ayj
V29uQXuP7csjIsMgQgK9r7A6eKBINK26ZKkOrub+QeQkC50RUqIpe21Vl2lsNJYi
FKF7NBAJ3cAveHHjwv/yvzATeiQb+5/6ujTH0w/YmqMQKJ/EPzHOavDB1O2tY9Gb
iuxnHTMj4K0hkuEWXMSKtBUXGOyHtcGlHLwuCt5OVKGAOcCA4jpazJpUSq8Dvvo9
dlf0r58U0EUQG77gTfsiKOFep3InxZeWjkKVINp30JagPVthjMPlP7nw53TfL+5F
Mc8lSjYKUiw=
=1J41
-----END PGP SIGNATURE-----