Vulnerabilities > Intel > High

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-11088 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-20
8.8
2019-12-18 CVE-2019-0169 Out-of-bounds Write vulnerability in Intel products
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.
low complexity
intel CWE-787
8.8
2019-12-18 CVE-2019-0166 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-20
7.5
2019-12-18 CVE-2019-0131 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.
low complexity
intel CWE-20
8.1
2019-12-16 CVE-2019-14610 Unspecified vulnerability in Intel products
Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel
7.8
2019-12-16 CVE-2019-14608 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-119
7.8
2019-12-16 CVE-2019-14605 Incorrect Default Permissions vulnerability in Intel Setup and Configuration Software Platform Discovery Utility
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.
local
low complexity
intel CWE-276
7.8
2019-12-16 CVE-2019-14603 Incorrect Default Permissions vulnerability in Intel Quartus Prime
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2019-12-16 CVE-2019-14599 Untrusted Search Path vulnerability in Intel Control Center-I 2.1.0.0
Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-426
7.8
2019-12-16 CVE-2019-14568 Incorrect Default Permissions vulnerability in Intel Rapid Storage Technology
Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8