CVE-2019-11087: Input Validation
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11087?
CVE-2019-11087 is a vulnerability in the subsystem for Intel(R) CSME and Intel(R) TXE that may allow a privileged user to potentially enable escalation of privilege, information disclosure, or denial of service.
What is the severity of CVE-2019-11087?
CVE-2019-11087 has a severity rating of 6.7 (Medium).
Which software versions are affected by CVE-2019-11087?
CVE-2019-11087 affects Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.70, 11.10 to 11.11.70, 11.20 to 11.22.70, 12.0 to 12.0.45, 13.0 to 13.0.10, 14.0.0 to 14.0.10, and Intel Trusted Execution Engine Firmware versions 3.0 to 3.1.70, 4.0 to 4.0.20.
How can a privileged user exploit CVE-2019-11087?
A privileged user can exploit CVE-2019-11087 by leveraging insufficient input validation in the subsystem for Intel(R) CSME and Intel(R) TXE, potentially enabling escalation of privilege, information disclosure, or denial of service.
Where can I find more information about CVE-2019-11087?
You can find more information about CVE-2019-11087 at the Intel Security Center advisory: [Link](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html)