IM
IronMonkey Threat Research

CVE-2017-5705 HIGH

Published: 2017-11-21 | Last Modified: 2026-06-17 | Status: Modified

Description

Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code.

Additional Descriptions (1)

Múltiples desbordamientos de búfer en el kernel en Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 permiten que un atacante con acceso local al sistema ejecute código arbitrario.

CVSS Metrics

Base Score: 7.2 (HIGH)

AV:L/AC:L/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
intel manageability_engine_firmware 11.0 <built-in method update of dict object at 0x7e60ba0aecc0> Operating System
intel manageability_engine_firmware 11.5 <built-in method update of dict object at 0x7e60a888cfc0> Operating System
intel manageability_engine_firmware 11.6 <built-in method update of dict object at 0x7e60a888fa80> Operating System
intel manageability_engine_firmware 11.7 <built-in method update of dict object at 0x7e60ba0ac980> Operating System
intel manageability_engine_firmware 11.10 <built-in method update of dict object at 0x7e60ba0ae040> Operating System
intel manageability_engine_firmware 11.20 <built-in method update of dict object at 0x7e60ba0ad440> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.5:*:*:*:*:*:*:*
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.10:*:*:*:*:*:*:*
Yes cpe:2.3:o:intel:manageability_engine_firmware:11.20:*:*:*:*:*:*:*

References

Notification
Message here