CVE-2020-12303: Intel Converged Security And Manageability Engine

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

Affected products

  • Intel Converged Security And Manageability Engine: before 11.8.80 (fixed in 11.8.80); from 11.12.0, before 11.12.80 (fixed in 11.12.80); from 11.22.0, before 11.22.80 (fixed in 11.22.80); from 12.0, before 12.0.70 (fixed in 12.0.70); from 14.0, before 14.0.45 (fixed in 14.0.45); from 14.5.0, before 14.5.25 (fixed in 14.5.25)
  • Intel Trusted Execution Technology: version 3.1.80 only; version 4.0.30 only

Published 2020-11-12. Last modified 2026-06-17.