CVE-2020-12303

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
12/11/2020
Last modified:
24/11/2020

Description

Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.8.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.12.0 (including) 11.12.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.22.0 (including) 11.22.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 12.0 (including) 12.0.70 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 14.0 (including) 14.0.45 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 14.5.0 (including) 14.5.25 (excluding)
cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*
cpe:2.3:a:intel:trusted_execution_technology:4.0.30:*:*:*:*:*:*:*