CVE-2020-0595Use After Free in Intel Active Management Technology Firmware

CWE-416Use After Free3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
2.8%
top 13.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 24

Description

Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDintel/service_manager11.011.8.77+3

🔴Vulnerability Details

2
GHSA
GHSA-v437-qvcx-v7cm: Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 112022-05-24
CVEList
CVE-2020-0595: Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 112020-06-15
CVE-2020-0595 — Use After Free in Intel | cvebase