CVE-2020-24525

Severity
7.8HIGH
EPSS
0.0%
top 88.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages24 packages

CVEListV5intel(r)_nucsSee references

🔴Vulnerability Details

2
GHSA
GHSA-r8m9-c8q4-99q2: Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of priv2022-05-24
CVEList
CVE-2020-24525: Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of priv2020-11-12