CVE-2017-5689
Intel Corporation Intel Active Mangement Technology, Intel Small Business Technology, Intel Standard Manageability
Published 2 May 2017 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 28 Jan 2022, with a remediation deadline of 28 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
References
- www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html · Patch, Third Party Advisory
- www.securityfocus.com/bid/98269 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1038385 · Broken Link, Third Party Advisory, VDB Entry
- cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf · Third Party Advisory
- downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf · Broken Link
- h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us · Third Party Advisory
- security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr · Patch, Vendor Advisory
- security.netapp.com/advisory/ntap-20170509-0001/ · Third Party Advisory
- www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf · Broken Link, Exploit, Technical Description
- www.embedi.com/news/mythbusters-cve-2017-5689 · Broken Link, Third Party Advisory
- www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability · Technical Description, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5689 · US Government Resource