CVE-2019-14609: Input Validation
Published Dec 16, 2019
·Updated
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
38 affected components
Intel Nuc 8 Mainstream Game Kit Firmware<0036
Intel Nuc 8 Mainstream Game Kit
Intel Nuc 8 Mainstream Game Mini Computer Firmware<0036
Intel Nuc 8 Mainstream Game Mini Computer
Intel Nuc8i7bek Firmware<0077
Intel Nuc8i7bek
Intel Cd1p64gk Firmware<0053
Intel Cd1p64gk
Intel Nuc8i3cysm Firmware<0043
Intel Nuc8i3cysm
Intel Nuc8i7hnk Firmware<0059
Intel Nuc8i7hnk
Intel Nuc7i7dnke Firmware<0067
Intel Nuc7i7dnke
Intel Nuc7i5dnke Firmware<0067
Intel Nuc7i5dnke
Intel Nuc7i3dnhe Firmware<0067
Intel Nuc7i3dnhe
Intel Stk2mv64cc Firmware<0061
Intel Stk2mv64cc
Intel Stk2m3w64cc Firmware<0062
Intel Stk2m3w64cc
Intel Nuc6i7kyk Firmware<0066
Intel Nuc6i7kyk
Intel Nuc6i5syh Firmware<0072
Intel Nuc6i5syh
Intel Nuc7cjyh Firmware<0053
Intel Nuc7cjyh
Intel Cd1m3128mk Firmware<0058
Intel Cd1m3128mk
Intel Cd1iv128mk Firmware<0038
Intel Cd1iv128mk
Intel Nuc6cays Firmware<0064
Intel Nuc6cays
Intel De3815tybe Firmware<0024
Intel De3815tybe
Intel D34010wyb Firmware<0054
Intel D34010wyb
Remediation
Event History
Dec 16, 2019
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-14609?
CVE-2019-14609 is a vulnerability in the firmware for Intel NUC that may allow a privileged user to potentially enable escalation of privilege via local access.
2
How severe is CVE-2019-14609?
CVE-2019-14609 has a severity rating of 6.7 (medium).
3
Which software versions are affected by CVE-2019-14609?
CVE-2019-14609 affects Intel NUC firmware versions up to and exclusive of 0036.
4
How can I fix CVE-2019-14609?
To fix CVE-2019-14609, update your Intel NUC firmware to version 0036 or higher.
5
Where can I find more information about CVE-2019-14609?
You can find more information about CVE-2019-14609 on the Intel Security Center Advisory page: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00323.html