VYPR
High severity7.8NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026

CVE-2020-12303

CVE-2020-12303

Description

Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

Affected products

5
  • cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:*
    Range: <11.8.80
  • cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*
    • cpe:2.3:a:intel:trusted_execution_technology:4.0.30:*:*:*:*:*:*:*
  • Intel/TXEllm-fuzzy
    Range: <3.1.80, <4.0.30
  • Intel/CSMEllm-fuzzy
    Range: <11.8.80, <11.12.80, <11.22.80, <12.0.70, <13.0.40, <13.30.10, <14.0.45, <14.5.25

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.