Description
Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00414
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Nov/26
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
11.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (23)
intel/nuc_8_mainstream-g_kit_nuc8i5inh_firmware
inwhl357.0036
intel/nuc_8_mainstream-g_kit_nuc8i7inh_firmware
inwhl357.0036
intel/nuc_8_mainstream-g_mini_pc_nuc8i5inh_firmware
inwhl357.0036
intel/nuc_8_mainstream-g_mini_pc_nuc8i7inh_firmware
inwhl357.0036
intel/nuc_8_pro_board_nuc8i3pnb_firmware
pnwhl357.0037
intel/nuc_8_pro_kit_nuc8i3pnh_firmware
pnwhl357.0037
intel/nuc_8_pro_kit_nuc8i3pnk_firmware
pnwhl357.0037
intel/nuc_8_pro_mini_pc_nuc8i3pnk_firmware
pnwhl357.0037
intel/nuc_8_rugged_kit_nuc8cchkr_firmware
chaplcel.0049
intel/nuc_9_pro_kit_nuc9v7qnx_firmware
qncflx70.34
... and 13 more
Published
Nov 12, 2020
Tracked Since
Feb 18, 2026