Unintended proxy or intermediary in Intel products - CVE-2021-33103
Published: May 16, 2022
Vulnerability identifier: #VU63178
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-33103
CWE-ID: CWE-441
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Rocket Lake Xeon
10th Generation Intel Core Processors
11th Generation Intel Core Processors
9th Generation Intel Core Processors
Rocket Lake Xeon
10th Generation Intel Core Processors
11th Generation Intel Core Processors
9th Generation Intel Core Processors
Software vendor:
Intel
Intel
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to presence of an unintended proxy in the BIOS authenticated code module. A local user can execute arbitrary code with elevated privileges.
Remediation
Install updates from vendor's website.