← Vulnerability feed

Vulnerability record · CVE-2020-8745 · published 12 November 2020

CVE-2020-8745: Intel converged security and manageability engine vulnerability

Intel · Converged Security And Manageability Engine

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

6.8 CVSS 3.1 Medium EPSS 0.38% · top 70.3%
6.8CVSS 3.1 base score, v2 4.6
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
22Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8745 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-5689Intel AMT, ISM and SBT improper privilege management allows privilege escalationIntel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges o…KEVEPSS 92%analysed8.2CVE-2021-41837Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM …EPSS 0.28%8.2CVE-2021-41838Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access …EPSS 0.30%8.2CVE-2021-42554Insydeh2o out-of-bounds write vulnerabilityAn issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 befor…EPSS 0.33%8.2CVE-2021-33627Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.…EPSS 0.33%7.8CVE-2021-33626Insydeh2o inclusion from untrusted sphere vulnerabilityA vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocat…EPSS 0.31%7.8CVE-2020-12297Intel converged security and manageability engine vulnerabilityImproper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14…EPSS 0.45%7.8CVE-2020-12303Intel converged security and manageability engine use after free vulnerabilityUse after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2020-8745), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.