VulnerabilityModified
CVE-2019-0096
Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an authenticated user to potentially enable escalation of privilege via adjacent network access.
HIGH 8.0EPSS 0.49%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an authenticated user to potentially enable escalation of privilege via adjacent network access.
- CVSS 3.1
- 8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.49% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- intel/active management technology firmware
- Source
- secure@intel.com
References
- https://support.f5.com/csp/article/K84591451Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.htmlVendor Advisory
- https://support.f5.com/csp/article/K84591451Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.