CVE-2019-11105: Intel Converged Security Management Engine Firmware

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.

Affected products

  • Intel Converged Security Management Engine Firmware: from 12.0, before 12.0.45 (fixed in 12.0.45); from 13.0, before 13.0.10 (fixed in 13.0.10); from 14.0.0, before 14.0.10 (fixed in 14.0.10)

Published 2019-12-18. Last modified 2026-06-17.