← Vulnerability feed

Vulnerability record · CVE-2017-5689 · published 2 May 2017

CVE-2017-5689: Intel AMT, ISM and SBT improper privilege management allows privilege escalation

Hpe · Proliant Ml10 Gen9 Server Firmware

Intel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges on provisioned systems, and an unprivileged local attacker can provision manageability features to gain network or local system privileges. Because AMT runs below the OS and is reachable over the network, compromise can be silent and persistent.

9.8 CVSS 3.1 Critical CISA KEV since 28 Jan 2022 EPSS 92% · top 0.2% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score, v2 10.0
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
36Affected product versions listed by NVD
23References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, KEV-listed, and an EPSS probability near 0.92 make this a top remediation priority.

What it is

Intel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges on provisioned systems, and an unprivileged local attacker can provision manageability features to gain network or local system privileges. Because AMT runs below the OS and is reachable over the network, compromise can be silent and persistent.

Impact

An attacker gains system-level privileges on affected Intel manageability platforms, enabling control of the machine independent of the operating system. This can allow persistent access, credential theft and lateral movement from a compromised endpoint.

Attack surface

Reachable over the network with no authentication or user interaction required (CVSS vector AV:N/PR:N/UI:N), and also locally by an unprivileged user. The flaw sits in the manageability firmware, not in a normal application.

Exploitation

Listed in CISA KEV since 2022-01-28 with a required action to apply vendor updates, and EPSS 30-day probability is about 0.92 (99.8th percentile). Reference tags include an Exploit and Technical Description link, indicating public technical detail exists.

What to do

  • Apply the Intel INTEL-SA-00075 firmware updates and the corresponding OEM (HPE, Siemens, Oracle, NetApp) advisories for affected platforms.
  • If patching is not immediately possible, apply the Intel mitigation guide steps, including unprovisioning AMT/ISM/SBT where the feature is not required.
  • Disable or unprovision manageability features on systems that do not need them, and restrict network access to management ports (TCP 16992/16993/623/664) to trusted management networks only.
  • Inventory endpoints and servers for Intel manageability SKUs and track which remain unpatched or provisioned.
  • Verify firmware versions after updating, since the flaw is in firmware rather than the host OS.

Detection

  • Monitor network traffic to Intel AMT/ISM management ports (16992, 16993, 623, 664) for unexpected or external sources.
  • Audit AMT/ISM provisioning state on managed endpoints and alert on changes to provisioning or management configuration.
  • Check firmware versions against vendor advisories to identify unpatched manageability SKUs.
  • Watch for anomalous out-of-band management activity or configuration changes that do not correlate with OS-level logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-5689 to the Known Exploited Vulnerabilities catalog on 28 January 2022 as "Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 28 July 2022.

Affected products

36 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.securityfocus.com/bid/98269 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038385 Broken LinkThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr PatchVendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Broken LinkExploitTechnical DescriptionThird Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Broken LinkThird Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical DescriptionThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.securityfocus.com/bid/98269 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038385 Broken LinkThird Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr PatchVendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Broken LinkExploitTechnical DescriptionThird Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Broken LinkThird Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical DescriptionThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5689 US Government Resource

Track CVE-2017-5689 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26845Intel active management technology firmware improper authentication vulnerabilityImproper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an una…EPSS 0.60%9.8CVE-2022-30601Intel standard manageability insufficiently protected credentials vulnerabilityInsufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable inf…EPSS 0.88%9.8CVE-2020-8752Intel active management technology firmware out-of-bounds write vulnerabilityOut-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unaut…EPSS 1.7%9.8CVE-2020-8758Intel standard manageability vulnerabilityImproper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 a…EPSS 1.9%9.8CVE-2020-0594Intel active management technology firmware out-of-bounds read vulnerabilityOut-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenti…EPSS 3.5%9.8CVE-2020-0595Intel active management technology firmware use after free vulnerabilityUse after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticate…EPSS 3.4%9.8CVE-2019-11131Intel active management technology firmware vulnerabilityLogic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially ena…EPSS 1.8%9.8CVE-2019-11107Intel active management technology firmware improper input validation vulnerabilityInsufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escala…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2017-5689), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.