Medium severity6.7NVD Advisory· Published Jun 13, 2019· Updated Jun 17, 2026
CVE-2018-12147
CVE-2018-12147
Description
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Intel(R)/CSMEdescription
<3.1.55+ 1 more
- (no CPE)range: <3.1.55
- cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*range: >=3.0,<=3.1.50
<4.0+ 1 more
- (no CPE)range: <4.0
- cpe:2.3:o:intel:server_platform_services_firmware:*:*:*:*:*:*:*:*range: <4.0
- cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*Range: >=11.0,<=11.8.50
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.