First published: Fri Nov 11 2022(Updated: )
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Nuc Kit Nuc8i7hnk Firmware | <hn0067 | |
Intel Nuc Kit Nuc8i7hnk | ||
Intel Nuc Kit Nuc8i7hvk Firmware | <hn0067 | |
Intel Nuc Kit Nuc8i7hvk | ||
Intel Nuc 8 Enthusiast Nuc8i7hvkva Firmware | <hn0067 | |
Intel Nuc 8 Enthusiast Nuc8i7hvkva | ||
Intel Nuc 8 Enthusiast Nuc8i7hvkvaw Firmware | <hn0067 | |
Intel Nuc 8 Enthusiast Nuc8i7hvkvaw | ||
Intel Nuc 8 Business Nuc8i7hnkqc Firmware | <hn0067 | |
Intel Nuc 8 Business Nuc8i7hnkqc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21794 is a vulnerability that allows a privileged user to potentially enable escalation of privilege via local access in some Intel NUC Boards, Intel NUC Business, Intel NUC Enthusiast, and Intel NUC Kits before version HN0067.
A privileged user can exploit CVE-2022-21794 through local access to gain escalated privileges.
The severity of CVE-2022-21794 is high with a severity score of 6.7.
Intel NUC Kits NUC8i7HNK and NUC8i7HVK, as well as Intel NUC 8 Enthusiast NUC8i7HVKVA and Intel NUC 8 Business NUC8i7HNKQC are affected by CVE-2022-21794.
To mitigate CVE-2022-21794, it is recommended to update the BIOS firmware of the affected Intel NUC Boards and Kits to version HN0067 or later.