CVE-2021-0163
Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- intel/amt ac 8260 firmware · intel/amt ac 8265 firmware · intel/amt ac 9260 firmware · intel/amt ac 9560 firmware · intel/amt wi-fi 6 ax200 firmware · intel/amt wi-fi 6 ax201 firmware · intel/amt wi-fi 6 ax210 firmware · intel/proset ac 3165 firmware · intel/proset ac 3168 firmware · intel/proset ac 8260 firmware · intel/proset ac 8265 firmware · intel/proset ac 9260 firmware · intel/proset ac 9461 firmware · intel/proset ac 9462 firmware · intel/proset ac 9560 firmware · intel/proset wi-fi 6 ax200 firmware · intel/proset wi-fi 6 ax201 firmware · intel/proset wi-fi 6e ax210 firmware · intel/proset wireless 7265 \(rev d\) firmware · intel/killer ac 1550 firmware · +2 more
- Source
- secure@intel.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.