CVE-2017-5708
published 2017-11-21CVE-2017-5708: Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.55%
42.4th percentile
Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecified vector.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra_10.13.3_security_update_2018-001_sierra_and_security_update_20 | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel | manageability_engine_firmware | — | — |
| intel_corporation | manageability_engine | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
cisa_ics·2018-03-01
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
Last RevisedApril 19, 2018
Alert CodeICSA-18-060-01
## 1. EXECUTIVE SUMMARY
## CVSS v3 8.2
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-060-01 Siemens SIMATIC, SIMOTION, and SINUMERIK that was published March 01, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in execution of arbitrary code, extended privileges, and unauthenticated access to sensitive data.
## 4. TECHNICAL DETAILS
## 4.1 AFFECT
Apple
CVE-2017-5708: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
vendor_apple·2018-01-23·CVSS 7.8
CVE-2017-5708 [HIGH] CVE-2017-5708: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
Apple Security Update: About the security content of macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
Product: macOS High Sierra 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan
CVE: CVE-2017-5708
Component: EFI
Description: Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecified vector.
GHSA
GHSA-gq44-jj6c-wc5c: Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11
ghsa_unreviewed·2022-05-13
CVE-2017-5708 [HIGH] GHSA-gq44-jj6c-wc5c: Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11
Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecified vector.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101921http://www.securitytracker.com/id/1039852https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfhttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frhttps://security.netapp.com/advisory/ntap-20171120-0001/https://www.asus.com/News/wzeltG5CjYaIwGJ0https://www.synology.com/support/security/Synology_SA_17_73http://www.securityfocus.com/bid/101921http://www.securitytracker.com/id/1039852https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfhttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frhttps://security.netapp.com/advisory/ntap-20171120-0001/https://www.asus.com/News/wzeltG5CjYaIwGJ0https://www.synology.com/support/security/Synology_SA_17_73
2017-11-21
Published