Potential security vulnerabilities in Intel® NUC® firmware may allow escalation of privilege.** **Intel is releasing firmware updates to mitigate these potential vulnerabilities.
CVEID: CVE-2019-14608
Description: Improper buffer restrictions in firmware for Intel® NUC® may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS Base Score: 7.8 High
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVEID: CVE-2019-14610
Description: Improper access control in firmware for Intel® NUC® may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS Base Score: 7.8 High
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVEID: CVE-2019-14609
Description: Improper input validation in firmware for Intel® NUC® may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Base Score: 7.5 High
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVEID: CVE-2019-14611
Description: Integer overflow in firmware for Intel® NUC® may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Base Score: 7.5 High
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVEID: CVE-2019-14612
Description: Out of bounds write in firmware for Intel® NUC® may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Base Score: 7.5 High
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Product
|
Updated Firmware
—|—
Intel® NUC 8 Mainstream Game Kit
|
Intel® NUC 8 Mainstream Game Mini Computer
|
Intel® NUC Kit NUC8i7BEK
|
Intel® Compute Card CD1P64GK
|
CD1P64GK__
Intel® NUC 8 Home - NUC8i3CYSM
|
Intel® NUC Kit NUC8i7HNK
|
Intel® NUC-Kit NUC7i7DNKE
|
Intel® NUC-Kit NUC7i5DNKE
|
Intel® NUC-Kit NUC7i3DNHE
|
Intel® Compute Stick STK2mv64CC
|
Intel® Compute Stick STK2m3W64CC
|
Intel® NUC Kit NUC6i7KYK
|
Intel® NUC Kit NUC6i5SYH
|
Intel® NUC Kit NUC7CJYH
|
NUC7CJYH__
Intel® Compute Card CD1M3128MK
|
Intel® Compute Card CD1IV128MK
|
Intel® NUC Kit NUC6CAYS
|
NUC6CAYS__
Intel® NUC Board DE3815TYBE
|
Intel® NUC Board D34010WYB
|
Intel recommends that users update to the latest version (see provided table).
Intel would like to thank Alexander Ermolov (CVE-2019-14608; CVE-2019-14609; CVE-2019-14610; CVE-2019-14612) and Dmitry Frolov (CVE-2019-14608; CVE-2019-14609; CVE-2019-14611) for reporting these issues and working with us on coordinated disclosure.
Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.