CVE-2017-5707

HIGH

Intel Trusted Execution Engine Firmware 3.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

References (7)

Core 7
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20171120-0001/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101919
Various Sources x_refsource_confirm
https://www.asus.com/News/wzeltG5CjYaIwGJ0

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (2)
intel/trusted_execution_engine_firmware 3.0
Intel Corporation/Trusted Execution Engine 3.0
Published Nov 21, 2017
Tracked Since Feb 18, 2026