First published: Wed Dec 18 2019(Updated: )
Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version 1.2.7.0 or before; INTEL-SA-00125 Detection Tool version 1.0.45.0 or before may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Intel-sa-00125 Detection Tool | <=1.0.45.0 | |
Intel Sa-00086 Detection Tool | <=1.2.7.0 | |
Intel Converged Security Management Engine Firmware | >=11.0<11.8.70 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.70 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.70 | |
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.0 | |
Intel Converged Security Management Engine Firmware | >=14.0.0<14.0.10 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.70 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11147 is a vulnerability in the hardware abstraction driver for MEInfo software for Intel CSME and TXEInfo software for Intel TXE.
CVE-2019-11147 allows attackers to gain unauthorized access to Intel systems.
CVE-2019-11147 has a severity rating of 7.8 (high).
To fix CVE-2019-11147, you should update the affected Intel software to the latest version available.
You can find more information about CVE-2019-11147 on the Intel Security Center advisory page at the following link: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html