IM
IronMonkey Threat Research

CVE-2017-5707 HIGH

Published: 2017-11-21 | Last Modified: 2026-06-17 | Status: Modified

Description

Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

Additional Descriptions (1)

Múltiples desbordamientos de búfer en el kernel en Trusted Execution Engine Firmware 3.0 permiten que un atacante con acceso local al sistema ejecute código arbitrario.

CVSS Metrics

Base Score: 7.2 (HIGH)

AV:L/AC:L/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
intel trusted_execution_engine_firmware 3.0 <built-in method update of dict object at 0x7e60ba0ad940> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:intel:trusted_execution_engine_firmware:3.0:*:*:*:*:*:*:*

References

Notification
Message here