Insufficient Access Control in Intel Capability Licensing Service
CVE-2018-12200

6.7MEDIUM

Summary

Insufficient access control in Intel Capability Licensing Service versions prior to 1.50.638.1 allows an unprivileged user to potentially escalate privileges through local access. This vulnerability can be exploited by users with local access to the system, thereby posing a risk to the security and integrity of the affected environments. It is crucial for users and administrators to ensure they are running the latest version of the software to mitigate potential threats. Further information can be found on the official Intel advisory and associated security bulletins.

Affected Version(s)

Intel(R) CSME, Server Platform Services, Trusted Execution Engine and Intel(R) Active Management Technology Multiple versions.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.