Unchecked Return Value in Intel products - CVE-2021-0114
Published: February 15, 2022
Vulnerability identifier: #VU60598
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-0114
CWE-ID: CWE-252
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
2nd Generation Intel Xeon Scalable Processors
Intel Xeon W Processors
Intel Xeon Processor E Family
Intel Xeon D Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Core X-series Processor Family
Intel Atom Processor C3XXX Family
Intel Xeon Scalable Processors
9th Generation Intel Core Processors
2nd Generation Intel Xeon Scalable Processors
Intel Xeon W Processors
Intel Xeon Processor E Family
Intel Xeon D Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Core X-series Processor Family
Intel Atom Processor C3XXX Family
Intel Xeon Scalable Processors
9th Generation Intel Core Processors
Detailed vulnerability description
The vulnerability allows a local administrator to escalate privileges on the system.
The vulnerability exists due to unchecked return value in the firmware, which leads to security restrictions bypass and privilege escalation.
How to mitigate CVE-2021-0114
Install updates from vendor's website.