CVE-2022-33176
Last modified
CVE-2022-33176 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Nuc 11 Performance Kit Nuc11pahi30z Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11pahi50z Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11pahi70z Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11pahi3 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11pahi5 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11pahi7 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11paki3 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11paki5 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Kit Nuc11paki7 Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Mini Pc Nuc11paqi50wa Firmware | < patgl357.0042 |
| Intel | Nuc 11 Performance Mini Pc Nuc11paqi70qa Firmware | < patgl357.0042 |
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00752.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00752.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33176?
How severe is CVE-2022-33176?
How do I fix CVE-2022-33176?
Are you affected by CVE-2022-33176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
