Intel Updates NUC Firmware to Patch High Severity Bug
#1
Quote:Intel today released a firmware update for multiple NUC Kit models to patch a high-severity issue that could be exploited to achieve privilege escalation, cause a denial-of-service (DoS) condition, or information disclosure.
 
NUC Kits are not the only small-form-factor computers from Intel requiring this update. A Compute Card and a Compute Stick run with the same BIOS and are equally affected by the bug.

Tracked as CVE-2019-11140, the vulnerability has a severity score of 7.5 out of 10 and it is due to insufficient validation.
 
Exploitation is possible if the attacker has local access with permissions of a privileged user; this would not be much of a hurdle for a determined attacker, though.
 
The full list of products in Intel's advisory affected by CVE-2019-11140 includes the following models:
  • Intel NUC Kit NUC7i7DNx
  • Intel NUC Kit NUC7i5DNx
  • Intel NUC Kit NUC7i3DNx
  • Intel Compute Stick STK2MV64CC
  • Intel Compute Card CD1IV128MK

Read more here: https://www.bleepingcomputer.com/news/se...erity-bug/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 151.0.1
Mozilla Firefox Br...harlan4096 — 08:57
AnyDesk 9.7.4 for Windows
Version 9.7.4 for ...harlan4096 — 08:55
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 08:52
Brave 1.90.124 (Chromium 148.0.7778.179)
Release v1.90.124 ...harlan4096 — 08:49
Screenpresso 2.2.12
Screenpresso 2.2.1...harlan4096 — 08:42

[-]
Birthdays
Today's Birthdays
avatar (40)odukoromu
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>