CVE-2020-0541: Intel Converged Security Management Engine Firmware
Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected products
- Intel Converged Security Management Engine Firmware: from 12.0, before 12.0.64 (fixed in 12.0.64); from 13.0, before 13.0.32 (fixed in 13.0.32); from 14.0, before 14.0.33 (fixed in 14.0.33); version 14.5.11 only
Published 2020-06-15. Last modified 2026-06-17.