SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-0530

Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

HIGH 7.8EPSS 0.34%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.34% probability · 27th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
intel/nuc kit nuc8i7bek firmware · intel/nuc 8 enthusiast pc nuc8i7bekqa firmware · intel/nuc kit nuc8i7hnk firmware · intel/nuc 8 business pc nuc8i7hnkqc firmware · intel/nuc 8 mainstream-g kit nuc8i7inh firmware · intel/nuc 8 mainstream-g kit nuc8i5inh firmware · intel/nuc 8 mainstream-g mini pc nuc8i7inh firmware · intel/nuc 8 rugged kit nuc8cchkr firmware · intel/nuc board nuc8cchb firmware · intel/nuc 8 home pc nuc8i3cysm firmware · intel/nuc kit nuc7i7dnke firmware · intel/nuc kit nuc7i7dnhe firmware · intel/nuc kit nuc7i5dnke firmware · intel/nuc kit nuc7i5dnhe firmware · intel/nuc kit nuc7i3dnke firmware · intel/nuc kit nuc7i3dnhe firmware · intel/nuc board nuc7i7dnbe firmware · intel/nuc board nuc7i5dnbe firmware · intel/nuc board nuc7i3dnbe firmware · intel/compute stick stk2m3w64cc firmware · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.