CVE-2018-3612

UnknownEPSS 0.32%

Last modified

CVE-2018-3612 is a vulnerability of currently unknown severity. Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).

Metrics

EPSS Probability
0.32%

23.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelBiosayaplcel.86a
IntelBiosbnkbl357.86a
IntelBiosccsklm5v.86a
IntelBiosccsklm30.86a
IntelBiosdnkbli5v.86a
IntelBiosdnkbli7v.86a
IntelBiosdnkbli30.86a
IntelBiosfybyt10h.86a
IntelBiosgkaplcpx.86a
IntelBioskyskli70.86a
IntelBiosmkkbli5v.86a
IntelBiosmkkbly35.86a
IntelBiosmybdwi5v.86a
IntelBiosmybdwi30.86a
IntelBiosrybdwi35.86a
IntelBiossyskli35.86a
IntelBiostybyt10h.86a
IntelAyaplcel.86aAll versions
IntelBnkbl357.86aAll versions
IntelCcsklm30.86aAll versions
IntelCcsklm5v.86aAll versions
IntelDnkbli30.86aAll versions
IntelDnkbli5v.86aAll versions
IntelDnkbli7v.86aAll versions
IntelFybyt10h.86aAll versions
IntelGkaplcpx.86aAll versions
IntelKyskli70.86aAll versions
IntelMkkbli5v.86aAll versions
IntelMkkbly35.86aAll versions
IntelMybdwi30.86aAll versions
IntelMybdwi5v.86aAll versions
IntelRybdwi35.86aAll versions
IntelSyskli35.86aAll versions
IntelTybyt10h.86aAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3612?
Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).
How severe is CVE-2018-3612?
Severity scoring for CVE-2018-3612 is pending analysis. The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3612?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3612?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST