CVE-2020-0528
Improper buffer restrictions in BIOS firmware for 7th, 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper buffer restrictions in BIOS firmware for 7th, 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- intel/core i5-7600k firmware · intel/core i5-7600t firmware · intel/core i5-7600 firmware · intel/core i5-7500 firmware · intel/core i5-7500t firmware · intel/core i5-7442eq firmware · intel/core i5-7440hq firmware · intel/core i5-7440eq firmware · intel/core i5-7400t firmware · intel/core i5-7400 firmware · intel/core i5-7360u firmware · intel/core i5-7300u firmware · intel/core i5-7300hq firmware · intel/core i5-7287u firmware · intel/core i5-7267u firmware · intel/core i5-7260u firmware · intel/core i5-7200u firmware · intel/core i5-7y54 firmware · intel/core i5-7y57 firmware · intel/core i7-7920hq firmware · +40 more
- Source
- secure@intel.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.