CVE-2022-36339

HIGH

Intel(R) NUC - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element may allow a privileged user to enable escalation of privilege via local access.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (13)
intel/cm11ebc4w_firmware < ebtgl357.0071
intel/cm11ebi38w_firmware < ebtgl357.0071
intel/cm11ebi58w_firmware < ebtgl357.0071
intel/cm11ebi716w_firmware < ebtgl357.0071
intel/cm8ccb4r_firmware < cbwhl357.0101
intel/cm8i3cb4n_firmware < cbwhl357.0101
intel/cm8i5cb8n_firmware < cbwhl357.0101
intel/cm8i7cb8n_firmware < cbwhl357.0101
intel/cm8pcb4r_firmware < cbwhl357.0101
intel/elm12hbc_firmware < hbadl357.0052
... and 3 more
Published May 10, 2023
Tracked Since Feb 18, 2026