First published: Wed Dec 18 2019(Updated: )
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11108 is a vulnerability in the subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 that may allow a privileged user to enable escalation of privilege via local access.
The severity of CVE-2019-11108 is medium, with a severity value of 6.7.
The Intel Converged Security Management Engine Firmware versions before 12.0.45 and 13.0.10 are affected by CVE-2019-11108.
A privileged user can potentially enable escalation of privilege via local access using CVE-2019-11108.
You can find more information about CVE-2019-11108 in the Intel Security Advisory SA-00241.