CVE-2022-26124Improper Restriction of Operations within the Bounds of a Memory Buffer in Intel NUC 8 Rugged Board Nuc8cchbn Firmware

Severity
7.8HIGHNVD
CNA7.5
EPSS
0.1%
top 84.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11

Description

Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rugged Kits before version CHAPLCEL.0059 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

2
CVEList
CVE-2022-26124: Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rug2022-11-11
GHSA
GHSA-4fx6-7wgg-hm24: Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rug2022-11-11
CVE-2022-26124 — Intel vulnerability | cvebase