CVE-2021-0067
moderate-risk
Published 2021-06-09
Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
Do I need to act?
-
0.06% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.7/10
Medium
LOCAL
/ LOW complexity
Affected Products (20)
Nuc M15 Laptop Kit Lapbc510 Firmware
Nuc M15 Laptop Kit Lapbc710 Firmware
Nuc 11 Compute Element Cm11Ebc4 Firmware
Nuc 11 Compute Element Cm11Ebi38W Firmware
Nuc 11 Compute Element Cm11Ebi58W Firmware
Nuc 11 Compute Element Cm11Ebi716W Firmware
Nuc 11 Performance Kit Nuc11Pahi3 Firmware
Nuc 11 Performance Kit Nuc11Pahi5 Firmware
Nuc 11 Performance Kit Nuc11Pahi7 Firmware
Nuc 11 Performance Kit Nuc11Paki3 Firmware
Nuc 11 Performance Kit Nuc11Paki5 Firmware
Nuc 11 Performance Kit Nuc11Paki7 Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi50Wa Firmware
Nuc 11 Performance Mini Pc Nuc11Paqi70Qa Firmware
Nuc 11 Pro Board Nuc11Tnbi3 Firmware
Nuc 11 Pro Board Nuc11Tnbi5 Firmware
Nuc 11 Pro Board Nuc11Tnbi7 Firmware
Nuc 11 Pro Kit Nuc11Tnhi3 Firmware
Nuc 11 Pro Kit Nuc11Tnhi30L Firmware
Nuc 11 Pro Kit Nuc11Tnhi30P Firmware
Affected Vendors
49
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
0/34 · Minimal
Exposure
28/34 · Critical