Improper access control in Converged Security and Management Engine (CSME) and Intel Trusted Execution Engine Firmware - CVE-2020-12297

 

Improper access control in Converged Security and Management Engine (CSME) and Intel Trusted Execution Engine Firmware - CVE-2020-12297

Published: November 12, 2020 / Updated: November 26, 2020


Vulnerability identifier: #VU48676
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12297
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in Installer. A local user can bypass implemented security restrictions and gain elevated privileges on the target system.


Affected software

Converged Security and Management Engine (CSME)
Intel Trusted Execution Engine Firmware

How to mitigate CVE-2020-12297

Install updates from vendor's website.

Converged Security and Management Engine (CSME) - addressed in versions 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45, 14.5.25
Intel Trusted Execution Engine Firmware - addressed in versions 3.1.80, 4.0.30

External References

Related Security Bulletins