Use After Free Vulnerability in Intel CSME and TXE Products
CVE-2020-12303
7.8HIGH
Summary
A use after free vulnerability in the Data Access Layer (DAL) subsystem of Intel's CSME and TXE products could potentially allow an authenticated user to escalate their privileges through local access. This issue affects multiple versions of CSME and TXE, making it crucial for users to ensure they are operating on supported and updated versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Intel(R) CSME, Intel(R) TXE Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved