Vulnerability Description
Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Nuc M15 Laptop Kit Lapbc510 Firmware | < bctgl357.0051 |
| Intel | Nuc M15 Laptop Kit Lapbc510 | - |
| Intel | Nuc M15 Laptop Kit Lapbc710 Firmware | < bctgl357.0051 |
| Intel | Nuc M15 Laptop Kit Lapbc710 | - |
| Intel | Nuc 11 Compute Element Cm11Ebc4 Firmware | < ebtgl357.0045 |
| Intel | Nuc 11 Compute Element Cm11Ebc4 | - |
| Intel | Nuc 11 Compute Element Cm11Ebi38W Firmware | < ebtgl357.0045 |
| Intel | Nuc 11 Compute Element Cm11Ebi38W | - |
| Intel | Nuc 11 Compute Element Cm11Ebi58W Firmware | < ebtgl357.0045 |
| Intel | Nuc 11 Compute Element Cm11Ebi58W | - |
| Intel | Nuc 11 Compute Element Cm11Ebi716W Firmware | < ebtgl357.0045 |
| Intel | Nuc 11 Compute Element Cm11Ebi716W | - |
| Intel | Nuc 11 Performance Kit Nuc11Pahi3 Firmware | < patgl357.0037 |
| Intel | Nuc 11 Performance Kit Nuc11Pahi3 | - |
| Intel | Nuc 11 Performance Kit Nuc11Pahi5 Firmware | < patgl357.0037 |
| Intel | Nuc 11 Performance Kit Nuc11Pahi5 | - |
| Intel | Nuc 11 Performance Kit Nuc11Pahi7 Firmware | < patgl357.0037 |
| Intel | Nuc 11 Performance Kit Nuc11Pahi7 | - |
| Intel | Nuc 11 Performance Kit Nuc11Paki3 Firmware | < patgl357.0037 |
| Intel | Nuc 11 Performance Kit Nuc11Paki3 | - |
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00511.PatchVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00511.PatchVendor Advisory
FAQ
What is CVE-2021-0067?
CVE-2021-0067 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2021-0067?
CVE-2021-0067 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-0067?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc M15 Laptop Kit Lapbc510 Firmware, Intel Nuc M15 Laptop Kit Lapbc510, Intel Nuc M15 Laptop Kit Lapbc710 Firmware, Intel Nuc M15 Laptop Kit Lapbc710, Intel Nuc 11 Compute Element Cm11Ebc4 Firmware.