High severity7.8NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-12303
CVE-2020-12303
Description
Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.
Affected products
5- cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:*Range: <11.8.80
cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*
- cpe:2.3:a:intel:trusted_execution_technology:4.0.30:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- security.netapp.com/advisory/ntap-20201113-0002/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20201113-0005/nvdThird Party Advisory
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391nvdVendor Advisory
News mentions
0No linked articles in our index yet.