#VU9393 Buffer overflow in Intel Manageability Firmware - CVE-2017-5712 

 

#VU9393 Buffer overflow in Intel Manageability Firmware - CVE-2017-5712

Published: November 22, 2017


Vulnerability identifier: #VU9393
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-5712
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Intel Manageability Firmware
Software vendor:
Intel

Description

The vulnerability allows a remote administrator to execute arbitrary code on the target system.

The weakness exists due to buffer overflow in Active Management Technology (AMT). A remote attacker with access to the system can send a specially crafted request, trigger memory corruption, execute arbitrary code with AMT execution privilege and compromise the vulnerable system.

Remediation

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

External links