CVE-2017-5712
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.41% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/manageability engine firmware · intel/active management technology firmware · asus/z170-premium firmware · asus/z170-deluxe firmware · asus/z170-pro firmware · asus/z170-a firmware · asus/z170-ar firmware · asus/z170-e firmware · asus/z170-k firmware · asus/z170-p firmware · asus/z170m-plus firmware · asus/z170m-plus\/br firmware · asus/z170-p d3 firmware · asus/z170m-e d3 firmware · asus/sabertooth z170 mark 1 firmware · asus/sabertooth z170 s firmware · asus/rog maximus viii extreme firmware · asus/rog maximus viii ranger firmware · asus/rog maximus viii formula firmware · asus/rog maximus viii hero firmware · +40 more
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/101920Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
- http://www.securityfocus.com/bid/101920Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.