First published: Wed Dec 18 2019(Updated: )
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.70 | |
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.10 | |
Intel Converged Security Management Engine Firmware | >=14.0.0<14.0.10 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.70 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11106 is a vulnerability in the Intel Converged Security Management Engine (CSME) and Trusted Execution Engine (TXE) firmware versions before 11.8.70, 12.0.45, 13.0.10, 14.0.10, 3.1.70, and 4.0.20.
The severity of CVE-2019-11106 is medium, with a severity value of 6.7.
CVE-2019-11106 can allow a privileged user to potentially enable escalation of privilege via local access to the Intel CSME subsystem.
CVE-2019-11106 can allow a privileged user to potentially enable escalation of privilege via local access to the Intel Trusted Execution Engine (TXE) firmware.
You can find more information about CVE-2019-11106 at the following reference: [Intel SA-00241](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html)