First published: Fri Nov 11 2022(Updated: )
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel NUC8i7HNK Firmware | <hn0067 | |
Intel NUC kit NUC8i7HNK | ||
Intel NUC 8i7HVK Firmware | <hn0067 | |
Intel NUC Kit NUC8i7HVK | ||
Intel NUC 8 Enthusiast NUC8i7HVKVAW Firmware | <hn0067 | |
Intel NUC 8 Enthusiast NUC8i7HVKVAW | ||
Intel NUC 8i7 HVKVAW Firmware | <hn0067 | |
Intel NUC 8 Enthusiast NUC8i7HVKVAW Firmware | ||
Intel NUC 8 Business NUC8i7HNKQC | <hn0067 | |
Intel NUC 8 Business NUC8i7HNKQC Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21794 is a vulnerability that allows a privileged user to potentially enable escalation of privilege via local access in some Intel NUC Boards, Intel NUC Business, Intel NUC Enthusiast, and Intel NUC Kits before version HN0067.
A privileged user can exploit CVE-2022-21794 through local access to gain escalated privileges.
The severity of CVE-2022-21794 is high with a severity score of 6.7.
Intel NUC Kits NUC8i7HNK and NUC8i7HVK, as well as Intel NUC 8 Enthusiast NUC8i7HVKVA and Intel NUC 8 Business NUC8i7HNKQC are affected by CVE-2022-21794.
To mitigate CVE-2022-21794, it is recommended to update the BIOS firmware of the affected Intel NUC Boards and Kits to version HN0067 or later.