First published: Thu Mar 14 2019(Updated: )
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.60 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.60 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.60 | |
Intel Converged Security Management Engine Firmware | >=12.0.0<12.0.20 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.60 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12189 is an unhandled exception vulnerability in the Content Protection subsystem in Intel CSME and Intel TXE.
CVE-2018-12189 may allow a privileged user to potentially modify data via local access.
Intel CSME versions 11.0 to 11.8.60, 11.10 to 11.11.60, 11.20 to 11.22.60, and 12.0.0 to 12.0.20 are affected by CVE-2018-12189.
Intel TXE versions 3.0 to 3.1.60 and 4.0 to 4.0.10 are affected by CVE-2018-12189.
CVE-2018-12189 has a severity score of 4.4, which is considered medium.
To fix the CVE-2018-12189 vulnerability, update Intel CSME to version 11.8.60, 11.11.60, 11.22.60, or 12.0.20, and update Intel TXE to version 3.1.60 or 4.0.10.