← Back

CVE-2019-11103

nvd nist
Published: Dec 18, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected (3)

1 product
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Intel
From 12.0 to 12.0.45
From 13.0 to 13.0.10
From 14.0.0 to 14.0.10

References (2)

Timeline

No history available yet.