CVE-2022-26124: Buffer Overflow
Published Nov 11, 2022
·Updated
Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rugged Kits before version CHAPLCEL.0059 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
16 affected components
intel Nuc 8 Rugged Kit Nuc8cchkrn Firmware<chaplcel.0059
intel Nuc 8 Rugged Kit Nuc8cchkrn
Intel Nuc 8 Rugged Kit Nuc8cchkr Firmware<chaplcel.0059
Intel Nuc 8 Rugged Kit Nuc8cchkr
intel Nuc 8 Rugged Board Nuc8cchbn Firmware<chaplcel.0059
Intel Nuc 8 Rugged Board Nuc8cchbn
Intel Nuc Board Nuc8cchb Firmware<chaplcel.0059
Intel Nuc Board Nuc8cchb
All of the following
intel Nuc 8 Rugged Kit Nuc8cchkrn Firmware<chaplcel.0059
intel Nuc 8 Rugged Kit Nuc8cchkrn
All of the following
Intel Nuc 8 Rugged Kit Nuc8cchkr Firmware<chaplcel.0059
Intel Nuc 8 Rugged Kit Nuc8cchkr
All of the following
intel Nuc 8 Rugged Board Nuc8cchbn Firmware<chaplcel.0059
Intel Nuc 8 Rugged Board Nuc8cchbn
All of the following
Intel Nuc Board Nuc8cchb Firmware<chaplcel.0059
Intel Nuc Board Nuc8cchb
Remediation
Event History
Nov 11, 2022
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this BIOS firmware vulnerability?
The vulnerability ID is CVE-2022-26124.
2
Which Intel products are affected by this vulnerability?
This vulnerability affects some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards, and Intel(R) NUC 8 Rugged Kits.
3
What is the severity rating of CVE-2022-26124?
The severity rating of CVE-2022-26124 is 7.8 out of 10, which is considered high.
4
How can a privileged user potentially exploit this vulnerability?
A privileged user can potentially enable escalation of privilege via local access.
5
Is there a fix available for this vulnerability?
Yes, a fix is available. Upgrade to BIOS firmware version CHAPLCEL.0059 or later to mitigate this vulnerability.