An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM)
Published May 2, 2017 ·Due Jul 28, 2022
9.8
CRITICALCVSS 3.1
EPSS 92.19%
Description
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Affected products
-
- Version fixed in versions 6.2.61.3535, 7.1.91.3272, 8.1.71.3608, 9.1.41.3024, 10.0.55.3000, 11.0.25.3001, and 11.6.27.3264 and laterStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Intel Corporation | n/a | n/a |
|
Configuration 1
Running on/with
- n/a
Configuration 2
- < 9.1.41.3024
Running on/with
- n/a
Configuration 3
- < 9.1.41.3024
Running on/with
- n/a
Configuration 4
- < 6.2.61.3535
Running on/with
- n/a
Configuration 5
- < 9.1.41.3024
Running on/with
- n/a
Configuration 6
- < 6.2.61.3535
Running on/with
- n/a
Configuration 7
- < 9.1.41.3024
Running on/with
- n/a
Configuration 8
- < 6.2.61.3535
Running on/with
- n/a
Configuration 9
- < 9.1.41.3024
Running on/with
- n/a
Configuration 10
- < 6.2.61.3535
Running on/with
- n/a
Configuration 11
- < 9.1.41.3024
Running on/with
- n/a
Configuration 12
- < 6.2.61.3535
Running on/with
- n/a
Configuration 13
- < 11.0.26.3000
Running on/with
- n/a
Configuration 14
- < 9.1.41.3024
Running on/with
- n/a
Configuration 15
- < 7.1.91.3272
Running on/with
- n/a
Configuration 16
- < 21.01.05
Running on/with
- n/a
Configuration 17
- n/a
- n/a
Running on/with
- n/a
Configuration 18
- < 6.2.61.3535
Running on/with
- n/a
Configuration 19
- < 18.01.06
Running on/with
- n/a
Configuration 20
- < 22.01.03
Running on/with
- n/a
Configuration 21
- < 9.1.41.3024
Running on/with
- n/a
Configuration 22
- < 9.1.41.3024
Running on/with
- n/a
Configuration 23
- < 21.01.04
Running on/with
- n/a
Configuration 24
- < 7.1.91.3272
Running on/with
- n/a
Configuration 25
- < 9.1.41.3024
Running on/with
- n/a
Configuration 26
- < 11.0.26.3000
Running on/with
- n/a
Configuration 27
- < 6.2.61.3535
Running on/with
- n/a
Configuration 28
- < 6.2.61.3535
Running on/with
- n/a
Configuration 29
- < 6.2.61.3535
Running on/with
- n/a
Configuration 30
- < 9.1.41.3024
Running on/with
- n/a
Configuration 31
- < 6.2.61.3535
Running on/with
- n/a
Configuration 32
- < 9.1.41.3024
Running on/with
- n/a
Configuration 33
- n/a
Running on/with
- n/a
Configuration 34
- < 11.0.26.3000
Running on/with
- n/a
Configuration 35
- n/a
Running on/with
- n/a
Configuration 36
- n/a
Running on/with
- n/a
Configuration 37
- < 21.01.05
Running on/with
- n/a
Configuration 38
- < 17.02.06.83.1
Running on/with
- n/a
Configuration 39
- < 6.2.61.3535
Running on/with
- n/a
Configuration 40
- 6.0
- 6.1
- 6.2
- 7.0
- 7.1
- 8.0
- 8.1
- 9.0
- 9.1
- 9.5
- 10.0
- 11.0
- 11.5
- 11.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Date Added
Jan 28, 2022
Patch Due
Jul 28, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 92.19% (0.92189) | 99.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 92.19% (0.92189) | 99.81th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.32% (0.94322) | 99.94th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.42% (0.97416) | 99.95th | v3 (v2023.03.01) |
| Feb 21, 2024 | 97.39% (0.97395) | 99.91th | v3 (v2023.03.01) |
| Aug 6, 2023 | 97.42% (0.97416) | 99.88th | v3 (v2023.03.01) |
| Jun 28, 2023 | 97.45% (0.97453) | 99.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.46% (0.97460) | 99.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 94.85% (0.94853) | 99.96th | v2 (v2022.01.01) |
| Oct 15, 2022 | 94.85% (0.94853) | 99.96th | v2 (v2022.01.01) |
| Feb 4, 2022 | 93.97% (0.93970) | 99.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 30.88% (0.30880) | 96.80th | v1 |
| Sep 1, 2021 | 30.88% (0.30880) | 98.57th | v1 |
| Apr 14, 2021 | 30.88% (0.30880) | 0.00th | v1 |
References (12)
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.securityfocus.com/bid/98269 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038385 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf x_refsource_CONFIRMThird Party Advisory
- https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf x_refsource_CONFIRMBroken Link
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us x_refsource_CONFIRMThird Party Advisory
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr x_refsource_CONFIRMPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20170509-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5689 government-resourceUS Government Resource
- https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf x_refsource_MISCBroken LinkExploitTechnical DescriptionThird Party Advisory
- https://www.embedi.com/news/mythbusters-cve-2017-5689 x_refsource_MISCBroken LinkThird Party Advisory
- https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability x_refsource_MISCTechnical DescriptionThird Party Advisory
Change history (0)
No recorded changes yet.