CVE-2018-12176: Input Validation

Published Sep 12, 2018
·
Updated

Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

Affected Software

29 affected components
Intel Nuc Kit Firmware
Intel Nuc Kit D33217gke
Intel Nuc Kit D53427rke
Intel Nuc Kit D54250wyb
Intel Nuc Kit De3815tybe
Intel Nuc Kit Dn2820fykh
Intel Nuc Kit Nuc5cpyh
Intel Nuc Kit Nuc5i3myhe
Intel Nuc Kit Nuc5i5myhe
Intel Nuc Kit Nuc5i7ryh
Intel Nuc Kit Nuc5pgyh
Intel Nuc Kit Nuc6cays
Intel Nuc Kit Nuc6i5syh
Intel NUC Kit NUC6i7KYK
Intel Nuc Kit Nuc7cjyh
Intel Nuc Kit Nuc7i3dnhe
Intel Nuc Kit Nuc7i5dnke
Intel Nuc Kit Nuc7i7bnh
Intel Nuc Kit Nuc7i7dnke
Intel Nuc Kit Nuc8i7hnk
Intel Compute Card Firmware
Intel Compute Card Cd1iv128mk
Intel Compute Card Cd1m3128mk
Intel Compute Card Cd1p64gk
Intel Compute Stick Firmware
Intel Compute Stick Stck1a32wfc
Intel Compute Stick Stk1aw32sc
Intel Compute Stick Stk2m3w64cc
Intel Compute Stick Stk2mv64cc

Event History

Sep 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-12176?

CVE-2018-12176 has a medium severity level due to the potential for information disclosure and privilege escalation.

2

How do I fix CVE-2018-12176?

To fix CVE-2018-12176, update the affected Intel NUC Kit firmware to the latest version provided by Intel.

3

Who is affected by CVE-2018-12176?

CVE-2018-12176 affects users of certain Intel NUC kits and compute cards with vulnerable firmware.

4

What types of attacks can CVE-2018-12176 enable?

CVE-2018-12176 may allow attackers to execute arbitrary code, escalate privileges, or cause denial of service via local access.

5

Is CVE-2018-12176 a remote or local vulnerability?

CVE-2018-12176 is a local vulnerability that requires physical access to the affected device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203