Multiple vulnerabilities in Intel NUC Firmware



Published: 2021-06-16
Risk Low
Patch available YES
Number of vulnerabilities 2
CVE ID CVE-2021-0067
CVE-2021-0054
CWE ID CWE-284
CWE-119
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Intel NUC M15 Laptop Kit - LAPBC510
Hardware solutions / Firmware

Intel NUC M15 Laptop Kit - LAPBC710
Hardware solutions / Firmware

Intel NUC 11 Compute Element CM11EBC4W
Hardware solutions / Firmware

Intel NUC 11 Compute Element CM11EBi38W
Hardware solutions / Firmware

Intel NUC 11 Compute Element CM11EBi58W
Hardware solutions / Firmware

Intel NUC 11 Compute Element CM11EBi716W
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAHi3
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAHi5
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAHi7
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAKi3
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAKi5
Hardware solutions / Firmware

Intel NUC 11 Performance kit - NUC11PAKi7
Hardware solutions / Firmware

Intel NUC 11 Performance Mini PC - NUC11PAQi50WA
Hardware solutions / Firmware

Intel NUC 11 Performance Mini PC - NUC11PAQi70QA
Hardware solutions / Firmware

Intel NUC 11 Pro Board NUC11TNBi3
Hardware solutions / Firmware

Intel NUC 11 Pro Board NUC11TNBi5
Hardware solutions / Firmware

Intel NUC 11 Pro Board NUC11TNBi7
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi3
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi30L
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi30P
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi5
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi50L
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi50W
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi7
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi70L
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNHi70Q
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNKi3
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNKi5
Hardware solutions / Firmware

Intel NUC 11 Pro Kit NUC11TNKi7
Hardware solutions / Firmware

Intel NUC 11 Enthusiast Kit - NUC11PHKi7C
Hardware solutions / Firmware

Intel NUC 11 Enthusiast Mini PC - NUC11PHKi7CAA
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i3FNH
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i3FNHF
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i3FNK
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i5FNH
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i5FNHF
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i5FNHJ
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i5FNK
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i5FNKP
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i7FNH
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i7FNHC
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i7FNK
Hardware solutions / Firmware

Intel NUC 10 Performance kit - NUC10i7FNKP
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i3FNHFA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i3FNHJA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i5FNHCA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i5FNHJA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i5FNKPA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i7FNHAA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i7FNHJA
Hardware solutions / Firmware

Intel NUC 10 Performance Mini PC - NUC10i7FNKPA
Hardware solutions / Firmware

Intel NUC 9 Pro Compute Element - NUC9V7QNB
Hardware solutions / Firmware

Intel NUC 9 Pro Compute Element - NUC9VXQNB
Hardware solutions / Firmware

Intel NUC 9 Pro Kit - NUC9V7QNX
Hardware solutions / Firmware

Intel NUC 9 Pro Kit - NUC9VXQNX
Hardware solutions / Firmware

Intel NUC 8 Business
Hardware solutions / Firmware

a Mini PC with Windows 10 - NUC8i7HNKQC
Hardware solutions / Firmware

Intel NUC 8 Enthusiast
Hardware solutions / Firmware

a Mini PC with Windows 10 - NUC8i7HVKVA
Hardware solutions / Firmware

a Mini PC with Windows 10 - NUC8i7HVKVAW
Hardware solutions / Firmware

Intel NUC Kit NUC8i7HNK
Hardware solutions / Firmware

Intel NUC Kit NUC8i7HVK
Hardware solutions / Firmware

Intel NUC 8 Rugged Kit NUC8CCHKR
Hardware solutions / Firmware

Intel NUC Board NUC8CCHB
Hardware solutions / Firmware

Intel NUC 8 Compute Element CM8CCB
Hardware solutions / Firmware

Intel NUC 8 Compute Element CM8i3CB
Hardware solutions / Firmware

Intel NUC 8 Compute Element CM8i5CB
Hardware solutions / Firmware

Intel NUC 8 Compute Element CM8i7CB
Hardware solutions / Firmware

Intel NUC 8 Compute Element CM8PCB
Hardware solutions / Firmware

Intel NUC 8 Pro Board NUC8i3PNB
Hardware solutions / Firmware

Intel NUC 8 Pro Kit NUC8i3PNH
Hardware solutions / Firmware

Intel NUC 8 Pro Kit NUC8i3PNK
Hardware solutions / Firmware

Intel NUC 8 Mainstream-G kit NUC8i5INH
Hardware solutions / Firmware

Intel NUC 8 Mainstream-G kit NUC8i7INH
Hardware solutions / Firmware

Intel NUC 8 Mainstream-G mini PC NUC8i5INH
Hardware solutions / Firmware

Intel NUC 8 Mainstream-G mini PC NUC8i7INH
Hardware solutions / Firmware

Intel NUC 7 Essential
Hardware solutions / Firmware

a Mini PC with Windows 10 - NUC7CJYSAL
Hardware solutions / Firmware

Intel NUC Kit NUC7CJYH
Hardware solutions / Firmware

Intel NUC Kit NUC7PJYH
Hardware solutions / Firmware

Vendor Intel

Security Advisory

1) Improper access control

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2021-0067

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in system firmware. A local administrator can bypass implemented security restrictions and gain elevated privileges on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Intel NUC M15 Laptop Kit - LAPBC510: All versions

Intel NUC M15 Laptop Kit - LAPBC710: All versions

Intel NUC 11 Compute Element CM11EBC4W: All versions

Intel NUC 11 Compute Element CM11EBi38W: All versions

Intel NUC 11 Compute Element CM11EBi58W: All versions

Intel NUC 11 Compute Element CM11EBi716W: All versions

Intel NUC 11 Performance kit - NUC11PAHi3: All versions

Intel NUC 11 Performance kit - NUC11PAHi5: All versions

Intel NUC 11 Performance kit - NUC11PAHi7: All versions

Intel NUC 11 Performance kit - NUC11PAKi3: All versions

Intel NUC 11 Performance kit - NUC11PAKi5: All versions

Intel NUC 11 Performance kit - NUC11PAKi7: All versions

Intel NUC 11 Performance Mini PC - NUC11PAQi50WA: All versions

Intel NUC 11 Performance Mini PC - NUC11PAQi70QA: All versions

Intel NUC 11 Pro Board NUC11TNBi3: All versions

Intel NUC 11 Pro Board NUC11TNBi5: All versions

Intel NUC 11 Pro Board NUC11TNBi7: All versions

Intel NUC 11 Pro Kit NUC11TNHi3: All versions

Intel NUC 11 Pro Kit NUC11TNHi30L: All versions

Intel NUC 11 Pro Kit NUC11TNHi30P: All versions

Intel NUC 11 Pro Kit NUC11TNHi5: All versions

Intel NUC 11 Pro Kit NUC11TNHi50L: All versions

Intel NUC 11 Pro Kit NUC11TNHi50W: All versions

Intel NUC 11 Pro Kit NUC11TNHi7: All versions

Intel NUC 11 Pro Kit NUC11TNHi70L: All versions

Intel NUC 11 Pro Kit NUC11TNHi70Q: All versions

Intel NUC 11 Pro Kit NUC11TNKi3: All versions

Intel NUC 11 Pro Kit NUC11TNKi5: All versions

Intel NUC 11 Pro Kit NUC11TNKi7: All versions

Intel NUC 11 Enthusiast Kit - NUC11PHKi7C: All versions

Intel NUC 11 Enthusiast Mini PC - NUC11PHKi7CAA: All versions

Intel NUC 10 Performance kit - NUC10i3FNH: All versions

Intel NUC 10 Performance kit - NUC10i3FNHF: All versions

Intel NUC 10 Performance kit - NUC10i3FNK: All versions

Intel NUC 10 Performance kit - NUC10i5FNH: All versions

Intel NUC 10 Performance kit - NUC10i5FNHF: All versions

Intel NUC 10 Performance kit - NUC10i5FNHJ: All versions

Intel NUC 10 Performance kit - NUC10i5FNK: All versions

Intel NUC 10 Performance kit - NUC10i5FNKP: All versions

Intel NUC 10 Performance kit - NUC10i7FNH: All versions

Intel NUC 10 Performance kit - NUC10i7FNHC: All versions

Intel NUC 10 Performance kit - NUC10i7FNK: All versions

Intel NUC 10 Performance kit - NUC10i7FNKP: All versions

Intel NUC 10 Performance Mini PC - NUC10i3FNHFA: All versions

Intel NUC 10 Performance Mini PC - NUC10i3FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNHCA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNKPA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNHAA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNKPA: All versions

Intel NUC 9 Pro Compute Element - NUC9V7QNB: All versions

Intel NUC 9 Pro Compute Element - NUC9VXQNB: All versions

Intel NUC 9 Pro Kit - NUC9V7QNX: All versions

Intel NUC 9 Pro Kit - NUC9VXQNX: All versions

Intel NUC 8 Business: All versions

a Mini PC with Windows 10 - NUC8i7HNKQC: All versions

Intel NUC 8 Enthusiast: All versions

a Mini PC with Windows 10 - NUC8i7HVKVA: All versions

a Mini PC with Windows 10 - NUC8i7HVKVAW: All versions

Intel NUC Kit NUC8i7HNK: All versions

Intel NUC Kit NUC8i7HVK: All versions

Intel NUC 8 Rugged Kit NUC8CCHKR: All versions

Intel NUC Board NUC8CCHB: All versions

Intel NUC 8 Compute Element CM8CCB: All versions

Intel NUC 8 Compute Element CM8i3CB: All versions

Intel NUC 8 Compute Element CM8i5CB: All versions

Intel NUC 8 Compute Element CM8i7CB: All versions

Intel NUC 8 Compute Element CM8PCB: All versions

Intel NUC 8 Pro Board NUC8i3PNB: All versions

Intel NUC 8 Pro Kit NUC8i3PNH: All versions

Intel NUC 8 Pro Kit NUC8i3PNK: All versions

Intel NUC 8 Mainstream-G kit NUC8i5INH: All versions

Intel NUC 8 Mainstream-G kit NUC8i7INH: All versions

Intel NUC 8 Mainstream-G mini PC NUC8i5INH: All versions

Intel NUC 8 Mainstream-G mini PC NUC8i7INH: All versions

Intel NUC 7 Essential: All versions

a Mini PC with Windows 10 - NUC7CJYSAL: All versions

Intel NUC Kit NUC7CJYH: All versions

Intel NUC Kit NUC7PJYH: All versions

CPE External links

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00511.html

Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Buffer overflow

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2021-0054

CWE-ID: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Exploit availability: No

Description

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in system firmware. A local administrator can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Intel NUC M15 Laptop Kit - LAPBC510: All versions

Intel NUC M15 Laptop Kit - LAPBC710: All versions

Intel NUC 11 Compute Element CM11EBC4W: All versions

Intel NUC 11 Compute Element CM11EBi38W: All versions

Intel NUC 11 Compute Element CM11EBi58W: All versions

Intel NUC 11 Compute Element CM11EBi716W: All versions

Intel NUC 11 Performance kit - NUC11PAHi3: All versions

Intel NUC 11 Performance kit - NUC11PAHi5: All versions

Intel NUC 11 Performance kit - NUC11PAHi7: All versions

Intel NUC 11 Performance kit - NUC11PAKi3: All versions

Intel NUC 11 Performance kit - NUC11PAKi5: All versions

Intel NUC 11 Performance kit - NUC11PAKi7: All versions

Intel NUC 11 Performance Mini PC - NUC11PAQi50WA: All versions

Intel NUC 11 Performance Mini PC - NUC11PAQi70QA: All versions

Intel NUC 11 Pro Board NUC11TNBi3: All versions

Intel NUC 11 Pro Board NUC11TNBi5: All versions

Intel NUC 11 Pro Board NUC11TNBi7: All versions

Intel NUC 11 Pro Kit NUC11TNHi3: All versions

Intel NUC 11 Pro Kit NUC11TNHi30L: All versions

Intel NUC 11 Pro Kit NUC11TNHi30P: All versions

Intel NUC 11 Pro Kit NUC11TNHi5: All versions

Intel NUC 11 Pro Kit NUC11TNHi50L: All versions

Intel NUC 11 Pro Kit NUC11TNHi50W: All versions

Intel NUC 11 Pro Kit NUC11TNHi7: All versions

Intel NUC 11 Pro Kit NUC11TNHi70L: All versions

Intel NUC 11 Pro Kit NUC11TNHi70Q: All versions

Intel NUC 11 Pro Kit NUC11TNKi3: All versions

Intel NUC 11 Pro Kit NUC11TNKi5: All versions

Intel NUC 11 Pro Kit NUC11TNKi7: All versions

Intel NUC 11 Enthusiast Kit - NUC11PHKi7C: All versions

Intel NUC 11 Enthusiast Mini PC - NUC11PHKi7CAA: All versions

Intel NUC 10 Performance kit - NUC10i3FNH: All versions

Intel NUC 10 Performance kit - NUC10i3FNHF: All versions

Intel NUC 10 Performance kit - NUC10i3FNK: All versions

Intel NUC 10 Performance kit - NUC10i5FNH: All versions

Intel NUC 10 Performance kit - NUC10i5FNHF: All versions

Intel NUC 10 Performance kit - NUC10i5FNHJ: All versions

Intel NUC 10 Performance kit - NUC10i5FNK: All versions

Intel NUC 10 Performance kit - NUC10i5FNKP: All versions

Intel NUC 10 Performance kit - NUC10i7FNH: All versions

Intel NUC 10 Performance kit - NUC10i7FNHC: All versions

Intel NUC 10 Performance kit - NUC10i7FNK: All versions

Intel NUC 10 Performance kit - NUC10i7FNKP: All versions

Intel NUC 10 Performance Mini PC - NUC10i3FNHFA: All versions

Intel NUC 10 Performance Mini PC - NUC10i3FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNHCA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i5FNKPA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNHAA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNHJA: All versions

Intel NUC 10 Performance Mini PC - NUC10i7FNKPA: All versions

Intel NUC 9 Pro Compute Element - NUC9V7QNB: All versions

Intel NUC 9 Pro Compute Element - NUC9VXQNB: All versions

Intel NUC 9 Pro Kit - NUC9V7QNX: All versions

Intel NUC 9 Pro Kit - NUC9VXQNX: All versions

Intel NUC 8 Business: All versions

a Mini PC with Windows 10 - NUC8i7HNKQC: All versions

Intel NUC 8 Enthusiast: All versions

a Mini PC with Windows 10 - NUC8i7HVKVA: All versions

a Mini PC with Windows 10 - NUC8i7HVKVAW: All versions

Intel NUC Kit NUC8i7HNK: All versions

Intel NUC Kit NUC8i7HVK: All versions

Intel NUC 8 Rugged Kit NUC8CCHKR: All versions

Intel NUC Board NUC8CCHB: All versions

Intel NUC 8 Compute Element CM8CCB: All versions

Intel NUC 8 Compute Element CM8i3CB: All versions

Intel NUC 8 Compute Element CM8i5CB: All versions

Intel NUC 8 Compute Element CM8i7CB: All versions

Intel NUC 8 Compute Element CM8PCB: All versions

Intel NUC 8 Pro Board NUC8i3PNB: All versions

Intel NUC 8 Pro Kit NUC8i3PNH: All versions

Intel NUC 8 Pro Kit NUC8i3PNK: All versions

Intel NUC 8 Mainstream-G kit NUC8i5INH: All versions

Intel NUC 8 Mainstream-G kit NUC8i7INH: All versions

Intel NUC 8 Mainstream-G mini PC NUC8i5INH: All versions

Intel NUC 8 Mainstream-G mini PC NUC8i7INH: All versions

Intel NUC 7 Essential: All versions

a Mini PC with Windows 10 - NUC7CJYSAL: All versions

Intel NUC Kit NUC7CJYH: All versions

Intel NUC Kit NUC7PJYH: All versions

CPE External links

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00511.html

Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###