CVE-2013-5740

UnknownEPSS 0.36%

Last modified

CVE-2013-5740 is a vulnerability of currently unknown severity. Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked, allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked, allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.

Metrics

EPSS Probability
0.36%

27.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelC202 ChipsetAll versions
IntelC204 ChipsetAll versions
IntelC206 ChipsetAll versions
IntelC216 ChipsetAll versions
IntelMobile Intel Qm67 ChipsetAll versions
IntelMobile Intel Qs67 ChipsetAll versions
IntelQ67 Express ChipsetAll versions
IntelQm77 ChipsetAll versions
IntelQs77 ChipsetAll versions
IntelTrusted Execution Technology Sinit Authenticated Code Module<= 1.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-5740?
Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked, allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.
How severe is CVE-2013-5740?
Severity scoring for CVE-2013-5740 is pending analysis. The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2013-5740?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-5740?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST