← Vulnerability feed

Vulnerability record · CVE-2019-0089 · published 17 May 2019

CVE-2019-0089: Intel server platform services vulnerability

Intel · Server Platform Services

Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.04.181.0, and SPS_SoC-X_04.00.04.086.0 may allow a privileged user to potentially enable escalation of privilege via local access.

6.7 CVSS 3.0 Medium EPSS 0.38% · top 70.4% CWE-19 · CWE-19
6.7CVSS 3.0 base score, v2 4.6
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.04.181.0, and SPS_SoC-X_04.00.04.086.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0089 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-36348Intel server platform services vulnerabilityActive debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalatio…EPSS 0.20%7.8CVE-2020-8744Intel converged security and management engine vulnerabilityImproper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4…EPSS 0.36%7.8CVE-2020-0586Intel server platform services vulnerabilityImproper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user…EPSS 0.37%7.1CVE-2019-0090Intel converged security and management engine vulnerabilityInsufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platfor…EPSS 0.36%6.8CVE-2020-8705Intel converged security and manageability engine insecure default initialization vulnerabilityInsecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13…EPSS 0.50%6.7CVE-2020-24509Intel server platform services vulnerabilityInsufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.02…EPSS 0.25%6.4CVE-2020-8755Intel converged security and management engine race condition vulnerabilityRace condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 m…EPSS 0.28%4.9CVE-2023-29153Intel server platform services uncontrolled resource consumption vulnerabilityUncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enab…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2019-0089), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.