Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIntel Active Management Technology Firmware
OSIntel11.0 – 11.8.77 (excl.)11.10 – 11.12.77 (excl.)11.20 – 11.22.77 (excl.)12.0 – 12.0.64 (excl.)Intel Service Manager
APPIntel11.0 – 11.8.77 (excl.)11.10 – 11.12.77 (excl.)11.20 – 11.22.77 (excl.)12.0 – 12.0.64 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References
Related vulnerabilities
CVE-2017-5689CRITICAL9.8⚠ KEVPL ✓same product
Privilege Escalation w Intel AMT/ISM/SBT — nieautoryzowany dostęp systemowy
CVE-2022-30601CRITICAL9.8PL ✓same product
Niewystarczająco chronione dane uwierzytelniające w Intel AMT i Intel Standard Manageability
CVE-2020-8752CRITICAL9.8PL ✓same product
Out-of-bounds write w IPv6 Intel AMT/ISM umożliwia privilege escalation
CVE-2020-8747CRITICAL9.1PL ✓same product
Out-of-bounds read w Intel AMT — ujawnienie danych i DoS przez sieć
CVE-2020-8758CRITICAL9.8PL ✓same product
Nieprawidłowe ograniczenia bufora w Intel AMT i ISM — privilege escalation przez sieć