Race condition in Intel products - CVE-2023-32282
Published: March 13, 2024
Vulnerability identifier: #VU87489
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32282
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in BIOS firmware. A local privileged user can exploit the race and escalate privileges on the system.
Affected software
Intel Celeron J6413
Intel Atom x6200FE
Intel Atom x6427FE
Intel Atom x6425RE
Intel Atom x6414RE
Intel Atom x6212RE
Intel Atom x6425E
Intel Atom x6413E
Intel Atom x6211E
Intel Pentium N6415
Intel Pentium J6425
Intel Celeron N6211
12th Generation Intel Core Processors
Intel Core i5-11500
Intel Core i5-11500T
Intel Core i5-11400
Intel Core i5-11400T
Intel Core i7-11700
Intel Core i7-11700T
10th Generation Intel Core Processors
11th Generation Intel Core Processors
Intel Celeron Processors
Intel Pentium Gold Processor Series
HPE ProLiant DL20 Gen11
HPE ProLiant ML30 Gen11
HPE ProLiant MicroServer Gen11
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
PowerSwitch Z9664F-ON
Intel Atom x6200FE
Intel Atom x6427FE
Intel Atom x6425RE
Intel Atom x6414RE
Intel Atom x6212RE
Intel Atom x6425E
Intel Atom x6413E
Intel Atom x6211E
Intel Pentium N6415
Intel Pentium J6425
Intel Celeron N6211
12th Generation Intel Core Processors
Intel Core i5-11500
Intel Core i5-11500T
Intel Core i5-11400
Intel Core i5-11400T
Intel Core i7-11700
Intel Core i7-11700T
10th Generation Intel Core Processors
11th Generation Intel Core Processors
Intel Celeron Processors
Intel Pentium Gold Processor Series
HPE ProLiant DL20 Gen11
HPE ProLiant ML30 Gen11
HPE ProLiant MicroServer Gen11
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant ML30 Gen10 Plus server
PowerSwitch Z9664F-ON
How to mitigate CVE-2023-32282
Install updates from vendor's website.
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen10 Plus - update to 2.00_02-01-2024
HPE ProLiant DL20 Gen10 Plus server - update to 2.00_02-01-2024
HPE ProLiant ML30 Gen10 Plus server - update to 2.00_02-01-2024
PowerSwitch Z9664F-ON - update to 3.54.5.1-9
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen10 Plus - update to 2.00_02-01-2024
HPE ProLiant DL20 Gen10 Plus server - update to 2.00_02-01-2024
HPE ProLiant ML30 Gen10 Plus server - update to 2.00_02-01-2024
PowerSwitch Z9664F-ON - update to 3.54.5.1-9