← Vulnerability feed

Vulnerability record · CVE-2020-8704 · published 9 June 2021

CVE-2020-8704: Intel local manageability service race condition vulnerability

Intel · Local Manageability Service

Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

6.4 CVSS 3.1 Medium EPSS 0.21% · top 90.1% CWE-362 · Race condition
6.4CVSS 3.1 base score, v2 4.4
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8704 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-5689Intel AMT, ISM and SBT improper privilege management allows privilege escalationIntel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges o…KEVEPSS 92%analysed8.2CVE-2021-41837Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM …EPSS 0.28%8.2CVE-2021-42554Insydeh2o out-of-bounds write vulnerabilityAn issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 befor…EPSS 0.33%8.2CVE-2021-41838Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access …EPSS 0.30%8.2CVE-2021-33627Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.…EPSS 0.33%7.8CVE-2021-33626Insydeh2o inclusion from untrusted sphere vulnerabilityA vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocat…EPSS 0.31%7.5CVE-2021-33625Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EF…EPSS 0.32%7.5CVE-2020-5953Insydeh2o vulnerabilityA vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT …EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2020-8704), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.