CVE-2019-11097: Intel Trusted Execution Engine Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected products

  • Intel Trusted Execution Engine Firmware: from 3.0, before 3.1.70 (fixed in 3.1.70); from 4.0, before 4.0.20 (fixed in 4.0.20)

Published 2019-12-18. Last modified 2026-06-17.