First published: Wed Dec 18 2019(Updated: )
Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.10 | |
Intel Converged Security Management Engine Firmware | >=14.0.0<14.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11105 is a logic issue in the subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10, and 14.0.10 that may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.
Intel Converged Security Management Engine Firmware versions 12.0.0 to 12.0.45, 13.0.0 to 13.0.10, and 14.0.0 to 14.0.10 are affected by CVE-2019-11105.
The severity of CVE-2019-11105 is medium with a CVSS score of 6.7.
To fix CVE-2019-11105, update the Intel Converged Security Management Engine Firmware to version 12.0.45, 13.0.10, or 14.0.10.
You can find more information about CVE-2019-11105 at the following reference: [Intel Security Center Advisory for CVE-2019-11105](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html).