CVE-2020-12303: Use After Free
Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12303?
CVE-2020-12303 is a vulnerability that allows an authenticated user to potentially enable escalation of privileges via local access in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, and Intel(R) TXE 3.1.80 and 4.0.30.
What is the severity of CVE-2020-12303?
The severity of CVE-2020-12303 is high with a CVSS score of 7.8.
How can an attacker exploit CVE-2020-12303?
An attacker can exploit CVE-2020-12303 by gaining authenticated local access and potentially enabling escalation of privileges.
Which software versions are affected by CVE-2020-12303?
Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45, and 14.5.25, and Intel(R) TXE 3.1.80 and 4.0.30 are affected by CVE-2020-12303.
Where can I find more information about CVE-2020-12303?
You can find more information about CVE-2020-12303 on the NetApp Security Advisory (NTAP-20201113-0002) and Intel Security Center Advisory (INTEL-SA-00391) websites.