CVE-2021-33117: Medium severity intel bios firmware vulnerability
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33117?
CVE-2021-33117 is a vulnerability related to improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7.
How does CVE-2021-33117 impact systems?
CVE-2021-33117 may allow a local attacker to potentially enable information disclosure via local access.
Which software versions are affected by CVE-2021-33117?
The affected software versions include 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7.
How can I fix CVE-2021-33117 on Ubuntu?
To fix CVE-2021-33117 on Ubuntu, update the 'intel-microcode' package to version 3.20220207.1 or later.
How can I fix CVE-2021-33117 on Debian?
To fix CVE-2021-33117 on Debian, update the 'intel-microcode' package to one of the following versions: 3.20220510.1~deb10u1, 3.20230808.1~deb10u1, 3.20230214.1~deb11u1, 3.20230808.1~deb11u1, 3.20230512.1, or 3.20230808.1~deb12u1.