First published: Tue May 02 2017(Updated: )
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Active Management Technology Firmware | =6.0 | |
Intel Active Management Technology Firmware | =6.1 | |
Intel Active Management Technology Firmware | =6.2 | |
Intel Active Management Technology Firmware | =7.0 | |
Intel Active Management Technology Firmware | =7.1 | |
Intel Active Management Technology Firmware | =8.0 | |
Intel Active Management Technology Firmware | =8.1 | |
Intel Active Management Technology Firmware | =9.0 | |
Intel Active Management Technology Firmware | =9.1 | |
Intel Active Management Technology Firmware | =9.5 | |
Intel Active Management Technology Firmware | =10.0 | |
Intel Active Management Technology Firmware | =11.0 | |
Intel Active Management Technology Firmware | =11.5 | |
Intel Active Management Technology Firmware | =11.6 | |
Intel Standard Manageability | ||
=6.0 | ||
=6.1 | ||
=6.2 | ||
=7.0 | ||
=7.1 | ||
=8.0 | ||
=8.1 | ||
=9.0 | ||
=9.1 | ||
=9.5 | ||
=10.0 | ||
=11.0 | ||
=11.5 | ||
=11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5689 is rated as critical due to its potential to allow an unprivileged network attacker to gain elevated privileges.
To remediate CVE-2017-5689, it is recommended to update to the latest firmware version of Intel Active Management Technology.
CVE-2017-5689 affects several versions of Intel Active Management Technology Firmware, including versions 6.0 to 11.6.
CVE-2017-5689 can be exploited by both unprivileged network and local attackers.
Currently, the primary mitigation for CVE-2017-5689 is to apply the available firmware updates from Intel.