Improper Access Control in Intel UEFI Integrator Tools for NUC Devices
CVE-2024-26022
7.8HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 August 2024
Summary
The vulnerability arises from improper access control mechanisms within Intel's UEFI Integrator Tools on Aptio V, specifically designed for Intel NUC systems. This flaw permits an authenticated user to gain elevated privileges locally, which could lead to unauthorized actions within the system. Given the nature of the hardware involved, it is critical for users and administrators of affected Intel UEFI Integrator Tools to assess their security posture and ensure that appropriate mitigations are in place to prevent exploitation.
Affected Version(s)
Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC See references
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved