Vulnerabilities > Intel > Trusted Execution Engine Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2018-12190 Improper Input Validation vulnerability in Intel products
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.
local
low complexity
intel CWE-20
4.6
2019-03-14 CVE-2018-12189 Improper Check for Unusual or Exceptional Conditions vulnerability in Intel products
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
local
low complexity
intel CWE-754
2.1
2019-03-14 CVE-2018-12188 Improper Input Validation vulnerability in Intel products
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
local
low complexity
intel CWE-20
2.1
2018-09-12 CVE-2018-3659 Unspecified vulnerability in Intel products
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
local
low complexity
intel
4.6
2018-09-12 CVE-2018-3655 Unspecified vulnerability in Intel products
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
local
low complexity
intel
3.6
2017-11-21 CVE-2017-5710 Unspecified vulnerability in Intel Trusted Execution Engine Firmware 3.0
Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unauthorized process to access privileged content via unspecified vector.
local
low complexity
intel
7.2
2017-11-21 CVE-2017-5707 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel Trusted Execution Engine Firmware 3.0
Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.
local
low complexity
intel CWE-119
7.2