Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
| Software | From | Fixed in |
|---|---|---|
| intel / converged_security_management_engine_firmware | 11.0 | 11.8.60 |
| intel / converged_security_management_engine_firmware | 11.10 | 11.11.60 |
| intel / converged_security_management_engine_firmware | 11.20 | 11.22.60 |
| intel / converged_security_management_engine_firmware | 12.0.0 | 12.0.20 |
| intel / trusted_execution_engine_firmware | 3.0 | 3.1.60 |
| intel / trusted_execution_engine_firmware | 4.0 | 4.0.10 |