Impact
Improper initialization in the firmware of Intel Active Management Technology (Intel AMT) and related Intel Standard Manageability components permits a local attacker who already holds privileged user rights to read sensitive data. The disclosed information can have high confidentiality impact, while integrity and availability are not affected. The weakness is characterized as CWE‑665 – Improper Initialization.
Affected Systems
Vulnerable firmware is found in Intel Active Management Technology (AMT) and Intel Standard Manageability products. No specific affected versions were announced, so all current firmware should be considered potentially impacted until the latest update from Intel is applied.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, and the EPSS score of less than 1% means the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access and a privileged user account; it is low in complexity and does not need user interaction or special internal knowledge.
OpenCVE Enrichment