SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24525

Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

HIGH 7.8EPSS 0.29%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.29% probability · 22th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
intel/nuc 8 mainstream-g kit nuc8i5inh firmware · intel/nuc 8 mainstream-g kit nuc8i7inh firmware · intel/nuc 8 mainstream-g mini pc nuc8i5inh firmware · intel/nuc 8 mainstream-g mini pc nuc8i7inh firmware · intel/nuc 8 pro board nuc8i3pnb firmware · intel/nuc 8 pro kit nuc8i3pnh firmware · intel/nuc 8 pro kit nuc8i3pnk firmware · intel/nuc 8 pro mini pc nuc8i3pnk firmware · intel/nuc 8 rugged kit nuc8cchkr firmware · intel/nuc 9 pro kit nuc9v7qnx firmware · intel/nuc 9 pro kit nuc9vxqnx firmware · intel/nuc board h27002-400 firmware · intel/nuc board h27002-401 firmware · intel/nuc board h27002-402 firmware · intel/nuc board h27002-404 firmware · intel/nuc board h27002-500 firmware · intel/nuc board nuc8cchb firmware · intel/nuc kit h26998-401 firmware · intel/nuc kit h26998-402 firmware · intel/nuc kit h26998-403 firmware · +3 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.