CVE-2017-5706

HIGH

Intel Server Platform Services Firmware 4.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101906
Issue Tracking, Third Party Advisory, Tool Signature x_refsource_confirm
https://security.netapp.com/advisory/ntap-20171120-0001/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039955
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Various Sources x_refsource_confirm
https://www.asus.com/News/wzeltG5CjYaIwGJ0

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
intel/server_platform_services_firmware 4.0
Intel Corporation/Server Platform Services 4.0
Published Nov 21, 2017
Tracked Since Feb 18, 2026