CVE-2020-12297: High severity intel converged security and manageability engine vulnerability
Improper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12297?
CVE-2020-12297 has a medium severity rating due to its potential for escalation of privileges.
How do I fix CVE-2020-12297?
To fix CVE-2020-12297, update the Intel CSME driver to a version later than 14.5.25 or the Intel TXE to a version later than 4.0.30.
Which Intel software is affected by CVE-2020-12297?
CVE-2020-12297 affects various versions of the Intel Converged Security and Management Engine and Intel Trusted Execution Technology.
What type of vulnerability is CVE-2020-12297?
CVE-2020-12297 is an access control vulnerability that can allow an authenticated user to escalate privileges.
Is local access required to exploit CVE-2020-12297?
Yes, local access is required to exploit CVE-2020-12297.