SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Intel fixes a high-severity vulnerability in CSME.

Intel fixes a high-severity vulnerability in CSME.

Feb 12, 2020By Vidita V Koushik2 min read

Intel patched a high-severity bug in the CSME subsystem, allowing an attacker to escalate privilege, disclose information, and deny service. Intel Converged Security and Management Engine (CSME) is a chipset subsystem that powers Intel’s Active Management technologies. CSME is used for remote out-of-band management in consumer or corporate PCs, Internet of Things (IoT) devices, and workstations. A reliable vulnerability management tool can help detect the vulnerabilities.

This bug was discovered internally by Intel’s security team and is tracked as CVE-2019-14598. CVE-2019-14598(INTEL-SA-00307) does not require any user interaction for exploitation and affects the system’s Confidentiality, Integrity, and Availability. But, the attacker needs to be a highly privileged user with local access to the system. To patch this vulnerability, a patch management tool is required.

Intel has also released medium and low-severity advisories for five other vulnerabilities. These vulnerabilities allow an authenticated user to escalate privileges via local access.

Advisories:

  • INTEL-SA-00273 : A vulnerability(CVE-2020-0560) in Intel® Renesas Electronics® USB 3.0 Driver exists due to an improper permissions issue in the installer. Intel has not released any updates to mitigate this vulnerability and has issued a Product Discontinuation notice for this product. Intel recommends that the usage of this drive discontinued or uninstalled at the earliest.
  • INTEL-SA-00336 : A vulnerability(CVE-2020-0561) in Intel® Software Guard Extensions (SGX) SDK exists due to an improper initialization issue.
  • INTEL-SA-00339 : A vulnerability CVE-2020-0562() in Intel® RAID Web Console 2 (RWC2) exists due to an improper permissions issue.
  • INTEL-SA-00340 : A vulnerability(CVE-2020-0563) in Intel® Manycore Platform Software Stack (MPSS) exists due to an improper permissions issue.
  • INTEL-SA-00341 : A vulnerability(CVE-2020-0564) in Intel® RAID Web Console 3 (RWC3) exists due to an improper permissions in the installer.

Impact

These vulnerabilities could allow attackers to escalate privileges, disclose sensitive information, or cause denial of service attacks.

Affected Products

  • Intel® CSME versions before 12.0.49 (IOT only: 12.0.56), 13.0.21, 14.0.11
  • All versions of Intel® Renesas Electronics® USB 3.0 Driver
  • Intel® SGX SDK before v2.6.100.1 for Windows, and Intel® SGX SDK before v2.8.100.1 for Linux
  • All versions of Intel® RWC2
  • Intel® MPSS before version 3.8.6.
  • Intel® RWC3 before version 7.010.009.000.

Solution

We recommend installing the Intel security updates as soon as possible to stay protected.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026