CVE-2018-12196: Intel Converged Security Management Engine Firmware

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.

Affected products

  • Intel Converged Security Management Engine Firmware: from 11.0, before 11.8.60 (fixed in 11.8.60); from 11.10, before 11.11.60 (fixed in 11.11.60); from 11.20, before 11.22.60 (fixed in 11.22.60); from 12.0.0, before 12.0.20 (fixed in 12.0.20)

Published 2019-03-14. Last modified 2026-06-17.