CVE-2017-5689

Intel Corporation Intel Active Mangement Technology, Intel Small Business Technology, Intel Standard Manageability

Published 2 May 2017 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 28 Jan 2022, with a remediation deadline of 28 Jul 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

References