PT-2022-5394 · Intel · Intel Nuc

Benny Zeltser

+1

·

Published

2022-11-08

·

Updated

2022-11-17

·

CVE-2021-33164

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) NUCs versions prior to INWHL357.0046
Description The issue is related to improper access control in BIOS firmware, which may allow a privileged user to potentially enable escalation of privilege via local access. It is also associated with a vulnerability in UEFI firmware, known as RingHopper, that allows code execution at the System Management Mode (SMM) level, providing unrestricted access to system memory. This vulnerability is linked to the possibility of conducting a timing attack using Direct Memory Access (DMA) to damage memory in SMM-level code. The presence of this vulnerability has been confirmed in Intel, Dell, and Insyde Software firmware, while AMD, Phoenix, and Toshiba firmware are not affected.
Recommendations For Intel(R) NUCs versions prior to INWHL357.0046, update the BIOS firmware to version INWHL357.0046 or later to resolve the issue. As a temporary workaround, consider restricting local access to the system to minimize the risk of exploitation. Avoid using DMA for sensitive operations until the issue is resolved.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2022-06708
CVE-2021-33164

Affected Products

Intel Nuc