Vulnerability record · CVE-2017-5689 · published 2 May 2017
CVE-2017-5689: Intel AMT, ISM and SBT improper privilege management allows privilege escalation
Hpe · Proliant Ml10 Gen9 Server Firmware
Intel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges on provisioned systems, and an unprivileged local attacker can provision manageability features to gain network or local system privileges. Because AMT runs below the OS and is reachable over the network, compromise can be silent and persistent.
Description
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, KEV-listed, and an EPSS probability near 0.92 make this a top remediation priority.
What it is
Intel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges on provisioned systems, and an unprivileged local attacker can provision manageability features to gain network or local system privileges. Because AMT runs below the OS and is reachable over the network, compromise can be silent and persistent.
Impact
An attacker gains system-level privileges on affected Intel manageability platforms, enabling control of the machine independent of the operating system. This can allow persistent access, credential theft and lateral movement from a compromised endpoint.
Attack surface
Reachable over the network with no authentication or user interaction required (CVSS vector AV:N/PR:N/UI:N), and also locally by an unprivileged user. The flaw sits in the manageability firmware, not in a normal application.
Exploitation
Listed in CISA KEV since 2022-01-28 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.92 (99.8th percentile). Reference tags include an Exploit and Technical Description link, indicating public technical detail exists.
What to do
- Apply the Intel INTEL-SA-00075 firmware updates and the corresponding OEM (HPE, Siemens, Oracle, NetApp) advisories for affected platforms.
- If patching is not immediately possible, apply the Intel mitigation guide steps, including unprovisioning AMT/ISM/SBT where the feature is not required.
- Disable or unprovision manageability features on systems that do not need them, and restrict network access to management ports (TCP 16992/16993/623/664) to trusted management networks only.
- Inventory endpoints and servers for Intel manageability SKUs and track which remain unpatched or provisioned.
- Verify firmware versions after updating, since the flaw is in firmware rather than the host OS.
Detection
- Monitor network traffic to Intel AMT/ISM management ports (16992, 16993, 623, 664) for unexpected or external sources.
- Audit AMT/ISM provisioning state on managed endpoints and alert on changes to provisioning or management configuration.
- Check firmware versions against vendor advisories to identify unpatched manageability SKUs.
- Watch for anomalous out-of-band management activity or configuration changes that do not correlate with OS-level logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-5689 to the Known Exploited Vulnerabilities catalog on 28 January 2022 as "Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 28 July 2022.
Affected products
36 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-5689 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5689), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.