CVE-2017-5712 is a buffer overflow vulnerability in Intel Active Management Technology (AMT) firmware versions 8.x through 11.20, affecting products from Intel, Asus, and Siemens. An attacker with remote administrative access can exploit this flaw to execute arbitrary code with AMT execution privileges. This high-severity vulnerability (CVSS 7.2) allows for complete compromise of confidentiality, integrity, and availability, requiring high privileges but no user interaction. While there is no public exploit code or evidence of active exploitation, it has garnered significant media attention and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0.0, <= 8.1.71.3608CPE matchmatch criteria | cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:* | ||
>= 9.0.0.0, <= 9.1.41.3024CPE matchmatch criteria | cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:* | ||
>= 10.0.0.0, <= 10.0.55.3000CPE matchmatch criteria | cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:intel:manageability_engine_firmware:11.0:*:*:*:*:*:*:* | ||
11.5CPE matchmatch criteria | cpe:2.3:o:intel:manageability_engine_firmware:11.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.