HIGH · 7.8

CVE-2021-0188

Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

Vulnerability Description

Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelXeon E3-1558L V5 Firmware-
IntelXeon E3-1558L V5-
IntelXeon E3-1565L V5 Firmware-
IntelXeon E3-1565L V5-
IntelXeon E3-1578L V5 Firmware-
IntelXeon E3-1578L V5-
IntelXeon E3-1585 V5 Firmware-
IntelXeon E3-1585 V5-
IntelXeon E3-1585L V5 Firmware-
IntelXeon E3-1585L V5-
IntelXeon E3-1515M V5 Firmware-
IntelXeon E3-1515M V5-
IntelXeon E3-1545M V5 Firmware-
IntelXeon E3-1545M V5-
IntelXeon E3-1575M V5 Firmware-
IntelXeon E3-1575M V5-
IntelXeon E3-1220 V5 Firmware-
IntelXeon E3-1220 V5-
IntelXeon E3-1225 V5 Firmware-
IntelXeon E3-1225 V5-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-0188?

CVE-2021-0188 is a vulnerability with a CVSS score of 7.8 (HIGH). Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

How severe is CVE-2021-0188?

CVE-2021-0188 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-0188?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Xeon E3-1558L V5 Firmware, Intel Xeon E3-1558L V5, Intel Xeon E3-1565L V5 Firmware, Intel Xeon E3-1565L V5, Intel Xeon E3-1578L V5 Firmware.