CVE-2011-5174
Last modified
CVE-2011-5174 is a vulnerability of currently unknown severity. Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before i5_i7_DUAL_SINIT_51.BIN and i7_QUAD_SINIT_51.BIN; Mobile Intel GM45, GS45, and PM45 Express Chipset before GM45_GS45_PM45_SINIT_51.BIN; Intel Q35 Express Chipsets before Q35_SINIT_51.BIN; and Intel 5520, 5500, X58, and 7500 Chipsets before SINIT ACM 1.1 allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before i5_i7_DUAL_SINIT_51.BIN and i7_QUAD_SINIT_51.BIN; Mobile Intel GM45, GS45, and PM45 Express Chipset before GM45_GS45_PM45_SINIT_51.BIN; Intel Q35 Express Chipsets before Q35_SINIT_51.BIN; and Intel 5520, 5500, X58, and 7500 Chipsets before SINIT ACM 1.1 allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Sinit Authenticated Code Module | <= 2nd_gen_i5_i7_sinit_1.9.bin |
| Intel | C202 Chipset | All versions |
| Intel | C204 Chipset | All versions |
| Intel | C206 Chipset | All versions |
| Intel | Mobile Intel Qm67 Chipset | All versions |
| Intel | Mobile Intel Qs67 Chipset | _express- |
| Intel | Q67 Express Chipset | All versions |
| Intel | Sinit Authenticated Code Module | <= i5_i7_dual_sinit_18.bin |
| Intel | 3450 Chipset | All versions |
| Intel | Mobile Intel Qm57 Chipset | All versions |
| Intel | Mobile Intel Qs57 Express Chipset | All versions |
| Intel | Q57 Chipset | All versions |
| Intel | Sinit Authenticated Code Module | <= i7_quad_sinit_20.bin |
| Intel | Mobile Intel Qs57 Chipset | All versions |
| Intel | Sinit Authenticated Code Module | <= gm45_gs45_pm45_sinit_21.bin |
| Intel | Mobile Intel Gm45 Chipset | All versions |
| Intel | Mobile Intel Gs45 Chipset | All versions |
| Intel | Mobile Intel Pm45 Express Chipset | All versions |
| Intel | Sinit Authenticated Code Module | <= q35_sinit_18.bin |
| Intel | Q35 Express Chipset | All versions |
| Intel | Sinit Authenticated Code Module | <= 1.0 |
| Intel | 5500 Chipset | All versions |
| Intel | 5520 Chipset | All versions |
| Intel | 7500 Chipset | All versions |
| Intel | X58 Chipset | All versions |
References
- http://secunia.com/advisories/47096Vendor Advisory
- http://secunia.com/advisories/47096Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-5174?
How severe is CVE-2011-5174?
How do I fix CVE-2011-5174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-5168SQL injection vulnerability in user.php in Banana Dance befo…
- CVE-2011-5169SQL injection vulnerability in sgms/reports/scheduledreports…
- CVE-2011-5170Stack-based buffer overflow in Castillo Bueno Systems CCMPla…
- CVE-2011-5171Multiple stack-based buffer overflows in CyberLink Power2Go …
- CVE-2011-5172Stack-based buffer overflow in StoryBoard Quick 6 Build 3786…
- CVE-2011-5173Buffer overflow in Bugbear Entertainment FlatOut 2005 allows…
- CVE-2011-5175SQL injection vulnerability in search.php in Banana Dance, p…
- CVE-2011-5176Multiple cross-site scripting (XSS) vulnerabilities in searc…
- CVE-2011-5177Multiple cross-site scripting (XSS) vulnerabilities in admin…
- CVE-2011-5178Multiple cross-site scripting (XSS) vulnerabilities in netmr…
- CVE-2011-5179Cross-site scripting (XSS) vulnerability in skysa-official/s…
- CVE-2011-5180Cross-site scripting (XSS) vulnerability in wp-1pluginjquery…
Are you affected by CVE-2011-5174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
