First published: Thu Nov 12 2020(Updated: )
Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Active Management Technology Software Development Kit | <14.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12354 refers to a vulnerability in the Windows installer in Intel AMT SDK versions before 14.0.0.1, which may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-12354 has a severity rating of 7.8 (high).
Intel AMT SDK versions before 14.0.0.1 are affected by CVE-2020-12354.
An authenticated user can potentially enable escalation of privilege via local access to exploit CVE-2020-12354.
Yes, you can find more information about CVE-2020-12354 at the following references: 1. [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20201113-0003/) 2. [Intel Security Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391)