Heap Overflow Vulnerability in Intel CSME and TXE Products
CVE-2019-0169

8.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
18 December 2019

Summary

A heap overflow vulnerability exists in the Intel CSME and TXE subsystems, allowing an unauthenticated user with adjacent access to exploit this weakness. Successful exploitation could lead to potential privilege escalation, unauthorized disclosure of information, or service disruption, thereby posing significant risks to affected systems. Users are advised to update to the latest versions to mitigate these risks.

Affected Version(s)

Intel(R) TXE See provided reference

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.