CVE-2021-33060
Description
Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Out-of-bounds write in BIOS firmware for select Intel processors allows local authenticated users to escalate privileges.
Vulnerability
An out-of-bounds write vulnerability exists in the BIOS firmware for some Intel(R) Processors, including certain 10th and 11th Generation Core processors, Intel Xeon processors, and related models. The vulnerability occurs in the BIOS firmware component and can be triggered by a local attacker with low privileges. The exact affected processor list is provided in Intel's security advisory (INTEL-SA-00686) [1].
Exploitation
An attacker must have authenticated access to the target system at a low-privilege (user) level. No additional user interaction is required beyond the attacker's own actions. The attacker can exploit this vulnerability by sending specially crafted inputs or requests to the BIOS firmware, causing an out-of-bounds write condition. The attack vector is local, meaning the attacker must be able to execute code on the machine, such as through a user account or malware already present on the system [1].
Impact
Successful exploitation of the out-of-bounds write allows the attacker to escalate privileges on the affected system. The attacker can potentially gain higher privileges, possibly up to system firmware level, leading to full compromise of the system's confidentiality, integrity, and availability. The vulnerability is classified with a CVSS score of 7.1, indicating a high severity [1].
Mitigation
Intel has released firmware updates to address this vulnerability. Users and system administrators should update their BIOS/UEFI firmware to the latest version provided by their system manufacturer (OEM). Intel's advisory [1] provides the fixed versions and links to OEM resources. There is no known workaround. The latest firmware versions for affected processors were released throughout 2022, with the advisory published on August 18, 2022 [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.netapp.com/advisory/ntap-20220930-0004/mitrex_refsource_CONFIRM
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00686.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.