CVE-2019-0091: Code Injection
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0091?
The severity of CVE-2019-0091 is high with a CVSS score of 7.8.
How does CVE-2019-0091 affect Intel Converged Security And Management Engine?
CVE-2019-0091 affects Intel Converged Security And Management Engine versions 11.8.0 to 11.8.65, 11.11.0 to 11.11.65, 11.22.0 to 11.22.65, and 12.0 to 12.0.35.
How does CVE-2019-0091 affect Intel Trusted Execution Technology?
CVE-2019-0091 affects Intel Trusted Execution Technology versions 3.1.0 to 3.1.65 and 4.0 to 4.0.15.
How can an unprivileged user exploit CVE-2019-0091?
An unprivileged user can potentially enable escalation of privilege via local access.
Is there a fix available for CVE-2019-0091?
Yes, Intel has released updates to address the code injection vulnerability in its installers for Intel(R) CSME and Intel(R) TXE.