Escalation of Privilege Vulnerability in Intel NUC BIOS Firmware
CVE-2023-28743

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
19 January 2024

Summary

A vulnerability exists in Intel NUC BIOS firmware versions prior to QN0073 due to improper input validation. This flaw can potentially be exploited by a privileged user who gains local access to escalate their privileges. The improper validation may allow a malicious user to manipulate certain inputs, thereby affecting the overall security posture of the system. Intel has released an advisory detailing this issue, and users are encouraged to update their firmware to the latest version to mitigate potential risks.

Affected Version(s)

Intel NUC BIOS firmware before version QN0073

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.