CVE-2019-0091

CWE-94Code Injection3 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 69.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 24

Description

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-wq4g-h799-937w: Code injection vulnerability in installer for Intel(R) CSME before versions 112022-05-24
CVEList
CVE-2019-0091: Code injection vulnerability in installer for Intel(R) CSME before versions 112019-05-17