CVE-2021-0196Incorrect Authorization in Intel Lapqc71a Firmware

Severity
7.8HIGHNVD
EPSS
0.1%
top 82.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

Improper access control in kernel mode driver for some Intel(R) NUC 9 Extreme Laptop Kits before version 2.2.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDintel/lapqc71a_firmware< 2.2.0.20
NVDintel/lapqc71b_firmware< 2.2.0.20
NVDintel/lapqc71c_firmware< 2.2.0.20
NVDintel/lapqc71d_firmware< 2.2.0.20

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6m3m-2q88-9qc9: Improper access control in kernel mode driver for some Intel(R) NUC 9 Extreme Laptop Kits before version 22022-05-24
CVEList
CVE-2021-0196: Improper access control in kernel mode driver for some Intel(R) NUC 9 Extreme Laptop Kits before version 22021-08-11
CVE-2021-0196 — Incorrect Authorization in Intel | cvebase