PT-2019-1662 · Intel · Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor+1

Published

2019-03-12

·

Updated

2019-10-03

·

CVE-2018-12205

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel Core Processor Platform Sample/Silicon Reference firmware for 8th Generation Intel Core Processor Intel Core Processor Platform Sample/Silicon Reference firmware for 7th Generation Intel Core Processor
Description The issue is related to inadequate access control and improper certificate validation in the firmware. This could potentially allow an unauthenticated user with physical access to escalate privileges. The exploitation of this issue may enable an attacker to execute arbitrary code.
Recommendations For 8th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls. For 7th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls. As a temporary workaround, consider restricting physical access to the devices until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01210
CVE-2018-12205

Affected Products

Intel Core Processor Platform Sample/Silicon Reference Firmware For 7Th Generation Intel Core Processor
Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor