Executive brief
Intel Endpoint Management Assistant (EMA) is a software tool used by IT administrators to remotely manage and repair computers. A security flaw in this software could allow an unauthorized person on the same local network to gain elevated administrative privileges on the system. This could lead to a complete takeover of the affected computer, allowing the attacker to access sensitive data or disrupt operations.
Technical details
A vulnerability in Intel Endpoint Management Assistant (EMA) software prior to version 1.14.5 is caused by improper input validation within Ring 3 (User Applications). The flaw allows an unauthenticated, unprivileged attacker with adjacent network access to achieve escalation of privilege. The attack is characterized by low complexity and requires no user interaction or special internal knowledge. Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability. Intel has released version 1.14.5 to mitigate this issue.
Affected products
- Intel Endpoint Management Assistant (EMA) before 1.14.5
Timeline
- 2026-05-12: disclosed: Initial advisory release by Intel
- 2026-05-12: patched: Update to version 1.14.5 released