CVE-2019-0086

Severity
7.8HIGH
EPSS
0.0%
top 85.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 24

Description

Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-7cpf-464x-jv68: Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 112022-05-24
CVEList
CVE-2019-0086: Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 112019-05-17

💬Community

3
Bugzilla
CVE-2019-17026 Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement2020-01-09
Bugzilla
CVE-2019-17017 Mozilla: Type Confusion in XPCVariant.cpp2020-01-07
Bugzilla
CVE-2019-17016 Mozilla: Bypass of @namespace CSS sanitization during pasting2020-01-07
CVE-2019-0086 (HIGH CVSS 7.8) | Insufficient access control vulnera | cvebase.io