MEDIUM · 6.7

CVE-2018-3632

Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be trig...

Vulnerability Description

Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be triggered by an attacker with local administrator permission on the system.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelActive Management Technology Firmware>= 6.0, <= 11.20
IntelCore 2 Duoe4300
IntelCore I34000m
IntelCore I54200h
IntelCore I74500u
IntelCore I98950hk
IntelCore 2 Extremeqx6700
IntelCore 2 Quadq6600
IntelCore 2 Solosu3500
IntelCore Duol2300
IntelCore Solot1250
IntelXeon Gold5115
IntelXeon Platinum8153
IntelXeon Silver4108
IntelXeonw2123

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-3632?

CVE-2018-3632 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be trig...

How severe is CVE-2018-3632?

CVE-2018-3632 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-3632?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Active Management Technology Firmware, Intel Core 2 Duo, Intel Core I3, Intel Core I5, Intel Core I7.