Vulnerability Description
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Manageability Engine Firmware | >= 8.0.0.0, <= 8.1.71.3608 |
| Intel | Active Management Technology Firmware | - |
| Asus | Z170-Premium Firmware | - |
| Asus | Z170-Premium | - |
| Asus | Z170-Deluxe Firmware | - |
| Asus | Z170-Deluxe | - |
| Asus | Z170-Pro Firmware | - |
| Asus | Z170-Pro | - |
| Asus | Z170-A Firmware | - |
| Asus | Z170-A | - |
| Asus | Z170-Ar Firmware | - |
| Asus | Z170-Ar | - |
| Asus | Z170-E Firmware | - |
| Asus | Z170-E | - |
| Asus | Z170-K Firmware | - |
| Asus | Z170-K | - |
| Asus | Z170-P Firmware | - |
| Asus | Z170-P | - |
| Asus | Z170M-Plus Firmware | - |
| Asus | Z170M-Plus | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101920Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039852Issue TrackingThird Party AdvisoryVDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageiIssue TrackingVendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue TrackingThird Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
- http://www.securityfocus.com/bid/101920Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039852Issue TrackingThird Party AdvisoryVDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageiIssue TrackingVendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue TrackingThird Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
FAQ
What is CVE-2017-5712?
CVE-2017-5712 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to exec...
How severe is CVE-2017-5712?
CVE-2017-5712 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5712?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Manageability Engine Firmware, Intel Active Management Technology Firmware, Asus Z170-Premium Firmware, Asus Z170-Premium, Asus Z170-Deluxe Firmware.