Vulnerabilities > Intel > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2018-12202 Unspecified vulnerability in Intel products
Privilege escalation vulnerability in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor may allow privileged user to potentially leverage existing features via local access.
local
low complexity
intel
7.2
2019-03-14 CVE-2018-12201 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Buffer overflow vulnerability in Platform Sample / Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor, Intel(R) Pentium(R) Silver J5005 Processor, Intel(R) Pentium(R) Silver N5000 Processor, Intel(R) Celeron(R) J4105 Processor, Intel(R) Celeron(R) J4005 Processor, Intel Celeron(R) N4100 Processor and Intel(R) Celeron N4000 Processor may allow privileged user to potentially execute arbitrary code via local access.
local
low complexity
intel CWE-119
7.2
2019-03-14 CVE-2018-12199 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
local
low complexity
intel CWE-119
7.2
2019-03-14 CVE-2018-12192 Improper Authentication vulnerability in Intel products
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
local
low complexity
intel CWE-287
7.2
2019-03-14 CVE-2018-12191 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
local
low complexity
intel CWE-119
7.2
2019-02-18 CVE-2019-0101 Unspecified vulnerability in Intel Unite 3.2/3.2.91.51/3.3
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.
network
low complexity
intel
7.5
2018-10-10 CVE-2018-12173 Incorrect Permission Assignment for Critical Resource vulnerability in Intel products
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
local
low complexity
intel CWE-732
7.2
2018-09-12 CVE-2018-3679 Unspecified vulnerability in Intel Data Center Manager
Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.
low complexity
intel
8.3
2018-09-12 CVE-2018-3669 Unspecified vulnerability in Intel Centrino Firmware
A STOP error (BSoD) in the ibtfltcoex.sys driver for Intel Centrino Wireless N and Intel Centrino Advanced N adapters may allow an unauthenticated user to potentially send a malformed L2CAP Connection Request is sent to the Intel Bluetooth device via the network.
network
low complexity
intel
7.8
2018-09-12 CVE-2018-12176 Improper Input Validation vulnerability in Intel products
Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
local
low complexity
intel CWE-20
7.2