NULL pointer dereference in Intel products - CVE-2021-0111

 

NULL pointer dereference in Intel products - CVE-2021-0111

Published: February 15, 2022


Vulnerability identifier: #VU60605
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0111
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a NULL pointer dereference error in the firmware. A local administrator can pass specially crafted data to the application and gain elevated privileges on the system.


Affected software

2nd Generation Intel Xeon Scalable Processors
Intel Xeon W Processors
Intel Xeon Processor E Family
Intel Xeon D Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
6th Generation Intel Core Processors
Intel Core X-series Processor Family
Intel Atom Processor C3XXX Family
VEP4600-8 Core
VEP4600-4 Core
VEP4600-16 Core
Intel Xeon Scalable Processors
9th Generation Intel Core Processors
IBM Qradar SIEM
EMC Integrated Data Protection Appliance
F5OS
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub

How to mitigate CVE-2021-0111

Install updates from vendor's website.

VEP4600-8 Core - update to UFW-3.8
VEP4600-4 Core - update to UFW-3.8
VEP4600-16 Core - update to UFW-3.8
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2210

External References

Related Security Bulletins