Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

Published at
2019-05-17
975 days ago
Modified
2020-01-23
724 days ago
2019
Year
The year of the turtle

https://support.f5.com/csp/article/K35815741

CONFIRM:https://support.f5.com/csp/article/K35815741

https://danishcyberdefence.dk/blog/dal

MISC:https://danishcyberdefence.dk/blog/dal

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html

MISC:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2019-0086"
	},
	"Notes": {
		"Note": [
			{
				"_text": "Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access."
			},
			{
				"_text": "2019-05-17"
			},
			{
				"_text": "2020-01-23"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2019-0086"
	},
	"References": {
		"Reference": [
			{
				"URL": {
					"_text": "https://support.f5.com/csp/article/K35815741"
				},
				"Description": {
					"_text": "CONFIRM:https://support.f5.com/csp/article/K35815741"
				}
			},
			{
				"URL": {
					"_text": "https://danishcyberdefence.dk/blog/dal"
				},
				"Description": {
					"_text": "MISC:https://danishcyberdefence.dk/blog/dal"
				}
			},
			{
				"URL": {
					"_text": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html"
				},
				"Description": {
					"_text": "MISC:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html"
				}
			}
		]
	}
}