Code Execution Vulnerability in Intel CSME and Server Platform Services
CVE-2018-12191
7.6HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 March 2019
Summary
A vulnerability exists in the Kernel subsystem of Intel CSME and Intel Server Platform Services that could allow an unauthenticated user to execute arbitrary code with physical access. This flaw affects multiple versions of Intel CSME, Server Platform Services, and Intel TXE, potentially enabling attackers to compromise the system integrity and gain unauthorized control.
Affected Version(s)
Intel(R) CSME, Server Platform Services, Trusted Execution Engine and Intel(R) Active Management Technology Multiple versions.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved