CVE-2017-5705General(intel / manageability_engine_firmware)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch intel manageability_engine_firmware systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • manageability_engine_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-08-29)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
manageability_engine_firmware

6 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-31: 1Mentions · 2026-08-29: 3Patch / Workaround · 2026-08-29: 1Technical Details · 2026-08-29: 203-3108-29
Signal classification3 categories
General
250.0%
False Positive
125.0%
Patch
125.0%
Classification over time
DateTotalLabels
2026-03-311
False Positive1
2026-08-293
General2Patch1
Full discourse4 posts
  • Trucku-Kun 📀@trucku_kun
    General

    @stylishcashfan @ky1ro @nyaa_sii @bee_fumo (2/2) If an attacker compromises ME via CVE-2017-5705 for example, they gain access to SMM/SPI controller registers to modify the BIOS region.

    Post summary

    The statement highlights the potential impact of CVE‑2017‑5705, noting that compromising the Management Engine could allow access to SMM/SPI controller registers and BIOS modification, but provides no evidence of exploitation, patches, or PoC.

    2000064
    39 followersView on X
  • Lexe@lexeapp
    False Positive

    @AJ__1337 That affects EOL Gemini Lake Atoms, a completely different microarchitecture from our Ice Lake Xeons. Different silicon, different CSME, separate GWK. The vuln chain (CVE-2017-5705 et al.) doesn't even exist on Ice Lake. Curious what CPU you are posting 'don't trust Intel' from?

    Post summary

    The tweet debunks the claim that CVE‑2017‑5705 affects Ice Lake CPUs, indicating the vulnerability does not apply to that architecture.

    0002082
    553 followersView on X
  • Trucku-Kun 📀@trucku_kun
    General

    @stylishcashfan @ky1ro @nyaa_sii @bee_fumo "Requires local access" is how 90% of malware chains operate Phishing email > Local execution > Exploit kernel > Pivot to ME (CVE-2017-5705). If local access made exploits "pointless," local privilege escalation (LPE) wouldn't be the most prized phase of modern attack chains.

    Post summary

    The tweet briefly mentions CVE-2017-5705 as part of a malware chain but provides no detailed or actionable information.

    1000063
    39 followersView on X
  • cashfan@stylishcashfan
    Patch

    @trucku_kun @ky1ro @nyaa_sii @bee_fumo i already said CVE-2017-5705 requires attackers to have local access, and if the attacker has local access already realistically there is no point in doing anything further they can already harvest data. also been patched 9 yr ago https://t.co/uvXnAfSBEq

    Post summary

    The author points out that CVE-2017-5705 only requires local access and has been patched for nine years, indicating it poses no current risk.

    1000050
    50 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSintelmanageability_engine_firmware11.0--
OSintelmanageability_engine_firmware11.10--
OSintelmanageability_engine_firmware11.20--
OSintelmanageability_engine_firmware11.5--
OSintelmanageability_engine_firmware11.6--
OSintelmanageability_engine_firmware11.7--

Explore more