VYPR
Unrated severityNVD Advisory· Published Jan 10, 2019· Updated Oct 2, 2024

CVE-2017-3718

CVE-2017-3718

Description

Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper device configuration in Intel NUC firmware allows a privileged user with physical access to escalate privileges.

Vulnerability

An improper setting of device configuration in the system firmware of certain Intel(R) NUC kits allows a privileged user to potentially escalate privileges. The vulnerability resides in the firmware configuration logic, which fails to enforce proper restrictions when a user with existing privileges modifies device settings. Affected models and firmware versions are detailed in the Intel security advisory [1].

Exploitation

Exploitation requires physical access to the target system and a user account with elevated privileges (e.g., local administrator). The attacker, having physical access, can manipulate the device configuration through the firmware interface to bypass security controls and gain higher privileges. No network access or user interaction beyond the attacker's own actions is needed [1].

Impact

Successful exploitation enables an attacker to escalate their privilege level, potentially achieving full control over the system. This could lead to unauthorized access to sensitive data, installation of persistent malware, or further compromise of the platform [1].

Mitigation

Intel has released firmware updates to address this vulnerability. Affected users should update their system firmware to the latest version provided by Intel for their specific NUC kit model. No workarounds are available; the fix is applied via a firmware update. Refer to the Intel security advisory for the list of affected models and the corresponding fixed firmware versions [1].

References
  1. INTEL-SA-00144

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Intel/NUC Kitsllm-fuzzy
  • Intel Corporation/Intel(R) NUCv5
    Range: Multiple versions.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.