SB2020061033 - Privilege escalation in Intel Innovation Engine



SB2020061033 - Privilege escalation in Intel Innovation Engine

Published: June 10, 2020

Security Bulletin ID SB2020061033
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-8675)

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to insufficient control flow management in firmware build and signing tool. An attacker with physical access can gain elevated privileges on the target system.


Remediation

Install update from vendor's website.