First published: Fri May 17 2019(Updated: )
Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | <12.0.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0153 is a vulnerability in the Intel Converged Security Management Engine Firmware that allows an unauthenticated user to potentially enable escalation of privilege through network access.
CVE-2019-0153 has a severity rating of critical, with a CVSS score of 9.8.
CVE-2019-0153 affects Intel CSME firmware versions 12.0.0 through 12.0.34, with 12.0.35 being the fixed version.
The CWE associated with CVE-2019-0153 is CWE-119, which is a flaw that allows buffer overflow.
To mitigate CVE-2019-0153, users should update to Intel CSME firmware version 12.0.35 or later.