GPU VulnDB

Database/Firmware, BMC & network fabric

Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalation

CVE-2019-0169Firmware, BMC & network fabriccurated

Impact

A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalation. Same shape and same consequence as the other network-reachable CSME overflows: code execution in the engine that sits under the OS.

Who can reach it

Unauthenticated attacker with access to the affected interface.

What to do

Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.