Code Execution Vulnerability in Intel CSME and Server Platform Services
CVE-2018-12191

7.6HIGH

Summary

A vulnerability exists in the Kernel subsystem of Intel CSME and Intel Server Platform Services that could allow an unauthenticated user to execute arbitrary code with physical access. This flaw affects multiple versions of Intel CSME, Server Platform Services, and Intel TXE, potentially enabling attackers to compromise the system integrity and gain unauthorized control.

Affected Version(s)

Intel(R) CSME, Server Platform Services, Trusted Execution Engine and Intel(R) Active Management Technology Multiple versions.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.