CVE-2019-0091

HIGH

Intel Converged Security and Management Engine < 11.8.65 - Unauthenticated Code Injection via Local Installer

Title source: llm
STIX 2.1

Description

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K21423526

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
intel/converged_security_and_management_engine 11.8.0 - 11.8.65
intel/trusted_execution_technology 3.1.0 - 3.1.65
Published May 17, 2019
Tracked Since Feb 18, 2026