Privilege Escalation Vulnerability in Intel NUC BIOS Firmware
CVE-2023-28738

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
19 January 2024

Summary

A vulnerability exists in Intel NUC BIOS firmware prior to version JY0070 due to improper input validation. This issue may allow a privileged user to exploit the flaw and potentially escalate privileges during local access. The improper handling of inputs can permit unauthorized elevation of user rights, thus posing significant security risks to affected systems.

Affected Version(s)

Intel NUC BIOS firmware before version JY0070

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.