CVE-2020-24457
Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
- CVSS 3.1
- 7.6 HIGHCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Affected
- intel/core i7-8665ue firmware · intel/core i7-8665u firmware · intel/core i7-8557u firmware · intel/core i7-8850h firmware · intel/core i7-8809g firmware · intel/core i7-8750h firmware · intel/core i7-8709g firmware · intel/core i7-8706g firmware · intel/core i7-8705g firmware · intel/core i7-8700t firmware · intel/core i7-8700k firmware · intel/core i7-8700b firmware · intel/core i7-8700 firmware · intel/core i7\+8700 firmware · intel/core i7-8569u firmware · intel/core i7-8650u firmware · intel/core i7-8565u firmware · intel/core i7-8559u firmware · intel/core i7-8550u firmware · intel/core i7-8500y firmware · +30 more
- Source
- secure@intel.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.