PT-2019-2116 · Intel · Intel Sps+3

Dmitry Sklyarov

+2

·

Published

2019-05-14

·

Updated

2020-08-24

·

CVE-2019-0090

CVSS v3.1

7.1

High

VectorAV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) CSME versions prior to 11.x Intel(R) TXE versions 3.x, 4.x Intel(R) Server Platform Services versions 3.x, 4.x Intel(R) SPS versions prior to SPS E3 05.00.04.027.0
Description The issue is related to insufficient access control in the Intel Converged Security and Management Engine, Intel Server Platform Services, and Intel Trusted Execution Engine. This could allow an unauthenticated user with physical access to potentially enable escalation of privilege. The vulnerability may also allow an attacker to extract the platform's root key, which is used as a root of trust for authenticating various platform components, including TPM and UEFI firmware. This could compromise cryptographic operations for hardware-enabled security technologies.
Recommendations For Intel(R) CSME versions prior to 11.x: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Intel(R) TXE versions 3.x, 4.x: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Intel(R) Server Platform Services versions 3.x, 4.x: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Intel(R) SPS versions prior to SPS E3 05.00.04.027.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01873
CVE-2019-0090

Affected Products

Intel Csme
Intel Sps
Intel Server Platform Services
Intel Txe