CVE-2018-3612: Input Validation
Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3612?
CVE-2018-3612 is a vulnerability in Intel NUC kits that allows a local attacker to elevate privileges to System Management Mode (SMM) due to insufficient input validation in the system firmware.
How severe is CVE-2018-3612?
CVE-2018-3612 has a severity score of 7.8 (high).
What software is affected by CVE-2018-3612?
Intel NUC kits with the following BIOS versions are affected: ayaplcel.86a, bnkbl357.86a, ccsklm5v.86a, ccsklm30.86a, dnkbli5v.86a, dnkbli7v.86a, dnkbli30.86a, fybyt10h.86a, gkaplcpx.86a, kyskli70.86a, mkkbli5v.86a, mkkbly35.86a, mybdwi5v.86a, mybdwi30.86a, rybdwi35.86a, syskli35.86a, tybyt10h.86a.
How can I fix CVE-2018-3612?
To fix CVE-2018-3612, it is recommended to update the BIOS firmware of the affected Intel NUC kits to the latest version provided by Intel.
Where can I find more information about CVE-2018-3612?
You can find more information about CVE-2018-3612 on Intel's official security advisory page: [Intel-SA-00110](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00110.html).