CVE-2019-0154

Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families may allow an authenticated user to potentially enable denial of service via local access.

Published: 2019-11-14 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-0154 is rated Low Risk (28/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.08%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-0154

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-30 1.49% 0.08% -1.41%
2 2025-03-29 0.07% 1.49% +1.42%
3 2024-11-07 0.07%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-0154

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 3.6 [email protected]
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2019-0154

OS Trackers for CVE-2019-0154

vendor priority summary link
debian not yet assigned CVE-2019-0154 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2019-0154
redhat medium https://access.redhat.com/security/cve/CVE-2019-0154
suse high CVE-2019-0154 severity important: SUSE including 601 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 910 product×package rows across 121 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-BYOS, … (121 product lines)): Fixed 720, Known Affected 157, Known Not Affected 33. https://www.suse.com/security/cve/CVE-2019-0154/
ubuntu medium CVE-2019-0154 medium priority: Ubuntu including 116 source packages (linux, linux-aws, …), 1218 status rows across 14 suites (bionic, cosmic, disco, eoan, focal, groovy, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 849, not-affected 172, released 162, ignored 31, needs-triage 3, needed 1. https://ubuntu.com/security/CVE-2019-0154

Affected software / configurations for CVE-2019-0154

Vendor Product Version Raw CPE
canonical ubuntu_linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
intel pentium_j4205_firmware < 26.20.100.6859 cpe:2.3:o:intel:pentium_j4205_firmware:*:*:*:*:*:windows:*:*
intel pentium_n4200_firmware < 26.20.100.6859 cpe:2.3:o:intel:pentium_n4200_firmware:*:*:*:*:*:windows:*:*
intel celeron_j3355_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_j3355_firmware:*:*:*:*:*:windows:*:*
intel celeron_j3455_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_j3455_firmware:*:*:*:*:*:windows:*:*
intel celeron_n3350_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_n3350_firmware:*:*:*:*:*:windows:*:*
intel celeron_n3450_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_n3450_firmware:*:*:*:*:*:windows:*:*
intel atom_x5-a3930_firmware < 26.20.100.6859 cpe:2.3:o:intel:atom_x5-a3930_firmware:*:*:*:*:*:windows:*:*
intel atom_x5-a3940_firmware < 26.20.100.6859 cpe:2.3:o:intel:atom_x5-a3940_firmware:*:*:*:*:*:windows:*:*
intel atom_x7-a3950_firmware < 26.20.100.6859 cpe:2.3:o:intel:atom_x7-a3950_firmware:*:*:*:*:*:windows:*:*
intel pentium_silver_j5005_firmware < 26.20.100.6859 cpe:2.3:o:intel:pentium_silver_j5005_firmware:*:*:*:*:*:windows:*:*
intel pentium_silver_n5000_firmware < 26.20.100.6859 cpe:2.3:o:intel:pentium_silver_n5000_firmware:*:*:*:*:*:windows:*:*
intel celeron_j4005_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_j4005_firmware:*:*:*:*:*:windows:*:*
intel celeron_j4105_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_j4105_firmware:*:*:*:*:*:windows:*:*
intel celeron_n4000_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_n4000_firmware:*:*:*:*:*:windows:*:*
intel celeron_n4100_firmware < 26.20.100.6859 cpe:2.3:o:intel:celeron_n4100_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6970hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6970hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6920hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6920hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6870hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6870hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6822eq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6822eq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6820hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6820hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6820hk_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6820hk_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6820eq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6820eq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6785r_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6785r_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6700k_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6700k_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6700t_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6700t_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6700te_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6700te_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6700_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6700_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6770hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6770hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6700hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6700hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6660u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6660u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6650u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6650u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6600u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6600u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6567u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6567u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6560u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6560u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-6500u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-6500u_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1585_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1585_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1585l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1585l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1578l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1578l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1575m_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1575m_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1565l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1565l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1558l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1558l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1545m_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1545m_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1535m_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1535m_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1515m_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1515m_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1505m_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1505m_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1505m_v5_firmware cpe:2.3:o:intel:xeon_e3-1505m_v5_firmware:-:*:*:*:*:*:*:*
intel xeon_e3-1505l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1505l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1280_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1280_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1275_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1275_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1270_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1270_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1268l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1268l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1260l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1260l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1245_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1245_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1240l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1240l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1240_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1240_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1235l_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1235l_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1230_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1230_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1225_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1225_v5_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1220_v5_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1220_v5_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7920hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7920hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7820hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7820hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7820hk_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7820hk_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7820eq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7820eq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7700hq_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7700hq_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7700_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7700_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7700k_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7700k_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7700t_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7700t_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7660u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7660u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7600u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7600u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7567u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7567u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7560u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7560u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7500u_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7500u_firmware:*:*:*:*:*:windows:*:*
intel core_i7-7y75_firmware < 26.20.100.6859 cpe:2.3:o:intel:core_i7-7y75_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1535m_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1535m_v6_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1505m_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1505m_v6_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1505l_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1505l_v6_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1501l_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1501l_v6_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1501m_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1501m_v6_firmware:*:*:*:*:*:windows:*:*
intel xeon_e3-1285_v6_firmware < 26.20.100.6859 cpe:2.3:o:intel:xeon_e3-1285_v6_firmware:*:*:*:*:*:windows:*:*

References for CVE-2019-0154

cvelogic Threat Intelligence