CVE-2019-11103: Input Validation
Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11103?
CVE-2019-11103 is a vulnerability in the firmware update software for Intel(R) CSME that allows an authenticated user to potentially escalate privileges via local access.
How does CVE-2019-11103 affect Intel Converged Security Management Engine Firmware?
CVE-2019-11103 affects Intel Converged Security Management Engine Firmware versions before 12.0.45, 13.0.10, and 14.0.10.
What is the severity of CVE-2019-11103?
CVE-2019-11103 has a severity rating of 7.8 (High).
How can an authenticated user exploit CVE-2019-11103?
An authenticated user can potentially enable escalation of privilege via local access by exploiting CVE-2019-11103.
How can I fix CVE-2019-11103?
To fix CVE-2019-11103, update your Intel Converged Security Management Engine Firmware to versions 12.0.45, 13.0.10, or 14.0.10.