PT-2017-3129 · Intel · Intel Manageability Engine Firmware
Jann Horn
·
Publicado
2017-11-20
·
Atualizado
2019-10-03
·
CVE-2017-5708
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel Manageability Engine Firmware versions 11.0 through 11.20
Description
The issue concerns multiple privilege escalations in the kernel of Intel Manageability Engine Firmware, allowing unauthorized processes to access privileged content. This is reportedly due to buffer overflow and insufficient access control measures. Exploitation of these issues could enable an attacker to elevate their privileges.
Recommendations
For Intel Manageability Engine Firmware versions 11.0 through 11.20, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Intel Manageability Engine Firmware