First published: Fri May 17 2019(Updated: )
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.65 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.65 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.65 | |
Intel Converged Security Management Engine Firmware | >=12.0<12.0.35 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.65 | |
Intel Trusted Execution Engine Firmware | >=4.0<=4.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0086 is an insufficient access control vulnerability in the Dynamic Application Loader software for Intel(R) CSME and Intel(R) TXE.
CVE-2019-0086 may allow an unprivileged user to potentially enable escalation of privilege via local access.
The affected software versions are Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35, and Intel(R) TXE 3.1.65, 4.0.15.
CVE-2019-0086 has a severity of 7.8 (High).
To fix CVE-2019-0086, it is recommended to update to the patched versions provided by Intel.