CVE-2022-28858Improper Restriction of Operations within the Bounds of a Memory Buffer in Intel Lapbc510 Firmware

Severity
7.8HIGHNVD
EPSS
0.1%
top 65.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateAug 19

Description

Improper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c469-p273-7c3p: Improper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable2022-08-19
CVEList
CVE-2022-28858: Improper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable2022-08-18
CVE-2022-28858 — Intel Lapbc510 Firmware vulnerability | cvebase