Improper Access Control in Intel UEFI Integrator Tools for NUC Devices
CVE-2024-26022

7.8HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 August 2024

Summary

The vulnerability arises from improper access control mechanisms within Intel's UEFI Integrator Tools on Aptio V, specifically designed for Intel NUC systems. This flaw permits an authenticated user to gain elevated privileges locally, which could lead to unauthorized actions within the system. Given the nature of the hardware involved, it is critical for users and administrators of affected Intel UEFI Integrator Tools to assess their security posture and ensure that appropriate mitigations are in place to prevent exploitation.

Affected Version(s)

Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC See references

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.