PT-2019-1662 · Intel · Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor+1
Published
2019-03-12
·
Updated
2019-10-03
·
CVE-2018-12205
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intel Core Processor Platform Sample/Silicon Reference firmware for 8th Generation Intel Core Processor
Intel Core Processor Platform Sample/Silicon Reference firmware for 7th Generation Intel Core Processor
Description
The issue is related to inadequate access control and improper certificate validation in the firmware. This could potentially allow an unauthenticated user with physical access to escalate privileges. The exploitation of this issue may enable an attacker to execute arbitrary code.
Recommendations
For 8th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls.
For 7th Generation Intel Core Processor firmware, update the firmware to a version that properly validates certificates and enforces access controls.
As a temporary workaround, consider restricting physical access to the devices until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Core Processor Platform Sample/Silicon Reference Firmware For 7Th Generation Intel Core Processor
Intel Core Processor Platform Sample/Silicon Reference Firmware For 8Th Generation Intel Core Processor