Improper input validation in Intel products - CVE-2019-14609
Published: December 12, 2019
Vulnerability identifier: #VU23551
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14609
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in firmware for Intel NUC. A local user can enable escalation of privilege on the target system.
Affected software
Intel Compute Stick STK2mv64CC
Intel NUC Board D34010WYB
Intel NUC Board DE3815TYBE
Intel NUC Kit NUC6CAYS
Intel Compute Card CD1IV128MK
Intel Compute Card CD1M3128MK
Intel NUC Kit NUC7CJYH
Intel NUC Kit NUC6i5SYH
Intel NUC Kit NUC6i7KYK
Intel Compute Stick STK2m3W64CC
Intel NUC 8 Mainstream Game Kit
Intel NUC-Kit NUC7i3DNHE
Intel NUC-Kit NUC7i5DNKE
Intel NUC-Kit NUC7i7DNKE
Intel NUC Kit NUC8i7HNK
Intel NUC 8 Home - NUC8i3CYSM
Intel Compute Card CD1P64GK
Intel NUC Kit NUC8i7BEK
Intel NUC 8 Mainstream Game Mini Computer
Intel NUC Board D34010WYB
Intel NUC Board DE3815TYBE
Intel NUC Kit NUC6CAYS
Intel Compute Card CD1IV128MK
Intel Compute Card CD1M3128MK
Intel NUC Kit NUC7CJYH
Intel NUC Kit NUC6i5SYH
Intel NUC Kit NUC6i7KYK
Intel Compute Stick STK2m3W64CC
Intel NUC 8 Mainstream Game Kit
Intel NUC-Kit NUC7i3DNHE
Intel NUC-Kit NUC7i5DNKE
Intel NUC-Kit NUC7i7DNKE
Intel NUC Kit NUC8i7HNK
Intel NUC 8 Home - NUC8i3CYSM
Intel Compute Card CD1P64GK
Intel NUC Kit NUC8i7BEK
Intel NUC 8 Mainstream Game Mini Computer
How to mitigate CVE-2019-14609
Install updates from vendor's website.