CVE-2019-0169: Intel Converged Security Management Engine Firmware
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.
Affected products
- Intel Converged Security Management Engine Firmware: from 11.0, before 11.8.70 (fixed in 11.8.70); from 11.10, before 11.11.70 (fixed in 11.11.70); from 11.20, before 11.22.70 (fixed in 11.22.70); from 12.0, before 12.0.45 (fixed in 12.0.45)
- Intel Trusted Execution Engine Firmware: from 3.0, before 3.1.70 (fixed in 3.1.70); from 4.0, before 4.0.20 (fixed in 4.0.20)
Published 2019-12-18. Last modified 2026-06-17.