Memory Corruption in Intel Active Management Technology Affecting Intel Converged Security Manageability Engine
CVE-2018-3632
6.7MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 10 July 2018
Summary
This vulnerability involves memory corruption within Intel's Active Management Technology, which can be exploited by an attacker possessing local administrator permissions on affected systems. If exploited, the vulnerability can allow unauthorized access to sensitive system functions, thereby compromising the integrity and confidentiality of information. The affected versions of the Intel Converged Security Manageability Engine Firmware range from 6.x to 11.20, making it crucial for users to ensure they are running updated and secure firmware to mitigate this risk.
Affected Version(s)
Intel Active Management Technology 3.x,4.x,5.x,6.x,7.x,8.x,9.x,10.x,11.x
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved