PT-2019-1628 · Intel · Intel Converged Security/Manageability Engine+1

Publicado

2019-03-12

·

Atualizado

2019-04-23

·

CVE-2018-12199

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel Converged Security and Manageability Engine (CSME) versions prior to 11.8.60, 11.11.60, 11.22.60, or 12.0.20 Intel Trusted Execution Engine (TXE) versions prior to 3.1.60 or 4.0.10
Description The issue is related to a buffer overflow in memory, which may allow an attacker to execute arbitrary code. This can potentially be exploited by a privileged user with physical access to the system.
Recommendations For Intel Converged Security and Manageability Engine (CSME) versions prior to 11.8.60, 11.11.60, 11.22.60, or 12.0.20, update to version 11.8.60, 11.11.60, 11.22.60, or 12.0.20 or later. For Intel Trusted Execution Engine (TXE) versions prior to 3.1.60 or 4.0.10, update to version 3.1.60, 4.0.10 or later. As a temporary workaround, consider restricting physical access to the system to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01175
CVE-2018-12199

Produtos afetados

Intel Converged Security/Manageability Engine
Intel Trusted Execution Engine