CVE-2017-5711
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/manageability engine firmware · intel/active management technology firmware · asus/z170-premium firmware · asus/z170-deluxe firmware · asus/z170-pro firmware · asus/z170-a firmware · asus/z170-ar firmware · asus/z170-e firmware · asus/z170-k firmware · asus/z170-p firmware · asus/z170m-plus firmware · asus/z170m-plus\/br firmware · asus/z170-p d3 firmware · asus/z170m-e d3 firmware · asus/sabertooth z170 mark 1 firmware · asus/sabertooth z170 s firmware · asus/rog maximus viii extreme firmware · asus/rog maximus viii ranger firmware · asus/rog maximus viii formula firmware · asus/rog maximus viii hero firmware · +40 more
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/101918Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
- http://www.securityfocus.com/bid/101918Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.