CVE-2019-11108: Input Validation
Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11108?
CVE-2019-11108 is a vulnerability in the subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 that may allow a privileged user to enable escalation of privilege via local access.
What is the severity of CVE-2019-11108?
The severity of CVE-2019-11108 is medium, with a severity value of 6.7.
Which software versions are affected by CVE-2019-11108?
The Intel Converged Security Management Engine Firmware versions before 12.0.45 and 13.0.10 are affected by CVE-2019-11108.
How can a privileged user exploit CVE-2019-11108?
A privileged user can potentially enable escalation of privilege via local access using CVE-2019-11108.
Where can I find more information about CVE-2019-11108?
You can find more information about CVE-2019-11108 in the Intel Security Advisory SA-00241.