MEDIUM · 6.7

CVE-2019-14609

Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerability Description

Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc 8 Mainstream Game Kit Firmware< 0036
IntelNuc 8 Mainstream Game Kit-
IntelNuc 8 Mainstream Game Mini Computer Firmware< 0036
IntelNuc 8 Mainstream Game Mini Computer-
IntelNuc8I7Bek Firmware< 0077
IntelNuc8I7Bek-
IntelCd1P64Gk Firmware< 0053
IntelCd1P64Gk-
IntelNuc8I3Cysm Firmware< 0043
IntelNuc8I3Cysm-
IntelNuc8I7Hnk Firmware< 0059
IntelNuc8I7Hnk-
IntelNuc7I7Dnke Firmware< 0067
IntelNuc7I7Dnke-
IntelNuc7I5Dnke Firmware< 0067
IntelNuc7I5Dnke-
IntelNuc7I3Dnhe Firmware< 0067
IntelNuc7I3Dnhe-
IntelStk2Mv64Cc Firmware< 0061
IntelStk2Mv64Cc-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14609?

CVE-2019-14609 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

How severe is CVE-2019-14609?

CVE-2019-14609 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14609?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc 8 Mainstream Game Kit Firmware, Intel Nuc 8 Mainstream Game Kit, Intel Nuc 8 Mainstream Game Mini Computer Firmware, Intel Nuc 8 Mainstream Game Mini Computer, Intel Nuc8I7Bek Firmware.