CVE-2020-0542

HIGH

Intel CSME Firmware <11.8.77, 12.0-12.0.64 - Privilege Escalation, Info Disclosure or DoS via Local Access

Title source: llm
STIX 2.1

Description

Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

References (3)

Core 3

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
intel/converged_security_management_engine_firmware 14.5.11
intel/converged_security_management_engine_firmware 11.0 - 11.8.77
intel/converged_security_management_engine_firmware 12.0 - 12.0.64
Published Jun 15, 2020
Tracked Since Feb 18, 2026