← Vulnerability feed

Vulnerability record · CVE-2019-0091 · published 17 May 2019

CVE-2019-0091: Intel converged security and management engine code injection vulnerability

Intel · Converged Security And Management Engine

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

7.8 CVSS 3.0 High EPSS 0.52% · top 58.2% CWE-94 · Code injection
7.8CVSS 3.0 base score, v2 7.2
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0091 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-8744Intel converged security and management engine vulnerabilityImproper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4…EPSS 0.36%7.8CVE-2020-12297Intel converged security and manageability engine vulnerabilityImproper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14…EPSS 0.45%7.8CVE-2020-12303Intel converged security and manageability engine use after free vulnerabilityUse after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel…EPSS 0.37%7.6CVE-2009-0066Intel trusted execution technology vulnerabilityMultiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integr…EPSS 2.2%7.1CVE-2019-0090Intel converged security and management engine vulnerabilityInsufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platfor…EPSS 0.36%6.8CVE-2020-8745Intel converged security and manageability engine vulnerabilityInsufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 …EPSS 0.38%6.8CVE-2020-8705Intel converged security and manageability engine insecure default initialization vulnerabilityInsecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13…EPSS 0.50%6.4CVE-2020-8755Intel converged security and management engine race condition vulnerabilityRace condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 m…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2019-0091), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.