SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-0099

Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

HIGH 7.8EPSS 0.30%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.30% probability · 23th percentile
CISA KEV
Not listed
Affected
intel/atom c3308 · intel/atom c3336 · intel/atom c3338 · intel/atom c3338r · intel/atom c3436l · intel/atom c3508 · intel/atom c3538 · intel/atom c3558 · intel/atom c3558r · intel/atom c3708 · intel/atom c3750 · intel/atom c3758 · intel/atom c3758r · intel/atom c3808 · intel/atom c3830 · intel/atom c3850 · intel/atom c3858 · intel/atom c3950 · intel/atom c3955 · intel/atom c3958 · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.