ZeroHour

CVE-2019-0086

CVSS 3.0
7.8 high
EPSS
<1%p29
Published
()
Modified
Description

Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

Vendors
intel
Products
converged security management engine firmware, trusted execution engine firmware
Weakness
CWE-59, CWE-732
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.