First published: Fri May 17 2019(Updated: )
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security And Management Engine | >=11.8.0<11.8.65 | |
Intel Converged Security And Management Engine | >=11.11.0<11.11.65 | |
Intel Converged Security And Management Engine | >=11.22.0<11.22.65 | |
Intel Converged Security And Management Engine | >=12.0<12.0.35 | |
Intel Trusted Execution Technology | >=3.1.0<3.1.65 | |
Intel Trusted Execution Technology | >=4.0<4.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0091 is high with a CVSS score of 7.8.
CVE-2019-0091 affects Intel Converged Security And Management Engine versions 11.8.0 to 11.8.65, 11.11.0 to 11.11.65, 11.22.0 to 11.22.65, and 12.0 to 12.0.35.
CVE-2019-0091 affects Intel Trusted Execution Technology versions 3.1.0 to 3.1.65 and 4.0 to 4.0.15.
An unprivileged user can potentially enable escalation of privilege via local access.
Yes, Intel has released updates to address the code injection vulnerability in its installers for Intel(R) CSME and Intel(R) TXE.