CVE-2017-5711
Last modified
CVE-2017-5711 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Manageability Engine Firmware | >= 8.0.0.0, <= 8.1.71.3608 |
| Intel | Manageability Engine Firmware | >= 9.0.0.0, <= 9.1.41.3024 |
| Intel | Manageability Engine Firmware | >= 10.0.0.0, <= 10.0.55.3000 |
| Intel | Manageability Engine Firmware | 11.0 |
| Intel | Manageability Engine Firmware | 11.5 |
| Intel | Manageability Engine Firmware | 11.6 |
| Intel | Manageability Engine Firmware | 11.7 |
| Intel | Manageability Engine Firmware | 11.10 |
| Intel | Manageability Engine Firmware | 11.20 |
| Intel | Active Management Technology Firmware | All versions |
| Asus | Z170-Premium Firmware | All versions |
| Asus | Z170-Deluxe Firmware | All versions |
| Asus | Z170-Pro Firmware | All versions |
| Asus | Z170-A Firmware | All versions |
| Asus | Z170-Ar Firmware | All versions |
| Asus | Z170-E Firmware | All versions |
| Asus | Z170-K Firmware | All versions |
| Asus | Z170-P Firmware | All versions |
| Asus | Z170m-Plus Firmware | All versions |
| Asus | Z170m-Plus\/Br Firmware | All versions |
| Asus | Z170-P D3 Firmware | All versions |
| Asus | Z170m-E D3 Firmware | All versions |
| Asus | Sabertooth Z170 Mark 1 Firmware | All versions |
| Asus | Sabertooth Z170 S Firmware | All versions |
| Asus | Rog Maximus Viii Extreme Firmware | All versions |
| Asus | Rog Maximus Viii Ranger Firmware | All versions |
| Asus | Rog Maximus Viii Formula Firmware | All versions |
| Asus | Rog Maximus Viii Hero Firmware | All versions |
| Asus | Rog Maximus Viii Hero Alpha Firmware | All versions |
| Asus | Rog Maximus Viii Gene Firmware | All versions |
| Asus | Rog Maximus Viii Impact Firmware | All versions |
| Asus | Z170i Pro Gaming Firmware | All versions |
| Asus | Z170 Pro Gaming Firmware | All versions |
| Asus | Z170 Pro Gaming\/Aura Firmware | All versions |
| Asus | B150 Pro Gaming Firmware | All versions |
| Asus | B150 Pro Gaming\/Aura Firmware | All versions |
| Asus | B150i Pro Gaming\/Wifi\/Aura Firmware | All versions |
| Asus | B150i Pro Gaming\/Aura Firmware | All versions |
| Asus | B150m Pro Gaming Firmware | All versions |
| Asus | B150m-A Firmware | All versions |
| Asus | B150m-A D3 Firmware | All versions |
| Asus | B150m-C D3 Firmware | All versions |
| Asus | B150-A Firmware | All versions |
| Asus | B150m-D Firmware | All versions |
| Asus | B150m-K Firmware | All versions |
| Asus | B150m-Plus Firmware | All versions |
| Asus | B150m-F Plus Firmware | All versions |
| Asus | B150-Plus Firmware | All versions |
| Asus | B150m-V Plus Firmware | All versions |
| Asus | Ex-B150m-V Firmware | All versions |
Showing 50 of 206 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/101918Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
- http://www.securityfocus.com/bid/101918Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039852Issue Tracking, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frIssue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20171120-0001/Issue Tracking, Third Party Advisory
- https://www.asus.com/News/wzeltG5CjYaIwGJ0Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5711?
How severe is CVE-2017-5711?
How do I fix CVE-2017-5711?
Are you affected by CVE-2017-5711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
