7.2
CVSSv2

CVE-2017-5705

Published: 21/11/2017 Updated: 11/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intel manageability engine firmware 11.0

intel manageability engine firmware 11.5

intel manageability engine firmware 11.10

intel manageability engine firmware 11.20

intel manageability engine firmware 11.6

intel manageability engine firmware 11.7

Vendor Advisories

Potential security vulnerabilities have been identified with certain versions of Intel Active Management Technology, Management Engine Firmware, and Management Engine Software The Cumulative Security update and WPA2 vulnerability fix impacts ME versions 11x, 10x, 9x, and 8x The Cumulative Security fix addresses vulnerabilities that c ...

Recent Articles

Intel to slap hardware lock on Management Engine code to thwart downgrade attacks
The Register • Thomas Claburn in San Francisco • 13 Dec 2017

From version 12 onward, ME-equipped chips will defend against patch rollbacks Intel's super-secret Management Engine firmware now glimpsed, fingered via USB

Intel's Coffee Lake and Cannon Lake x86 processors can be fortified by computer manufacturers to prevent in hardware attempts to downgrade, exploit and potentially neuter Chipzilla's built-in creepy Management Engine. In June, Positive Technologies security researchers Mark Ermolov and Maxim Goryachy privately reported to Intel a brace of exploitable bugs – CVE-2017-5705, 5706, and 5707 – in the powerful Management Engine's firmware. Last month, in response and ahead of Ermolov and Goryachy'...

Intel Management Engine pwned by buffer overflow
The Register • Thomas Claburn in San Francisco • 06 Dec 2017

Security researchers lift lid on snafu at Black Hat Europe

On Wednesday, in a presentation at Black Hat Europe, Positive Technologies security researchers Mark Ermolov and Maxim Goryachy plan to explain the firmware flaws they found in Intel Management Engine 11, along with a warning that vendor patches for the vulnerability may not be enough. Two weeks ago, the pair received thanks from Intel for working with the company to disclose the bugs responsibility. At the time, Chipzilla published 10 vulnerability notices affecting its Management Engine (ME), ...

Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets
The Register • Thomas Claburn in San Francisco • 20 Nov 2017

Bugs can be exploited to extract info, potentially insert rootkits Intel ME controller chip has secret kill switch

Intel today admitted its Management Engine (ME), Server Platform Services (SPS), and Trusted Execution Engine (TXE) are vulnerable to multiple worrying security flaws, based on the findings of external security experts. The firmware-level bugs allow logged-in administrators, and malicious or hijacked high-privilege processes, to run code beneath the operating system to spy on or meddle with the computer completely out of sight of other users and admins. The holes can also be exploited by network...