CVE-2018-12190

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/03/2019
Last modified:
01/05/2019

Description

Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.0 (including) 11.8.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.10 (including) 11.11.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.20 (including) 11.22.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.20 (excluding)
cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:* 3.0 (including) 3.1.60 (excluding)
cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:* 4.0 (including) 4.0.10 (excluding)