CVE-2017-3718
Description
Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper device configuration in Intel NUC firmware allows a privileged user with physical access to escalate privileges.
Vulnerability
An improper setting of device configuration in the system firmware of certain Intel(R) NUC kits allows a privileged user to potentially escalate privileges. The vulnerability resides in the firmware configuration logic, which fails to enforce proper restrictions when a user with existing privileges modifies device settings. Affected models and firmware versions are detailed in the Intel security advisory [1].
Exploitation
Exploitation requires physical access to the target system and a user account with elevated privileges (e.g., local administrator). The attacker, having physical access, can manipulate the device configuration through the firmware interface to bypass security controls and gain higher privileges. No network access or user interaction beyond the attacker's own actions is needed [1].
Impact
Successful exploitation enables an attacker to escalate their privilege level, potentially achieving full control over the system. This could lead to unauthorized access to sensitive data, installation of persistent malware, or further compromise of the platform [1].
Mitigation
Intel has released firmware updates to address this vulnerability. Affected users should update their system firmware to the latest version provided by Intel for their specific NUC kit model. No workarounds are available; the fix is applied via a firmware update. Refer to the Intel security advisory for the list of affected models and the corresponding fixed firmware versions [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Intel Corporation/Intel(R) NUCv5Range: Multiple versions.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00144.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.