VYPR
Unrated severityNVD Advisory· Published Aug 18, 2022· Updated May 5, 2025

CVE-2021-33847

CVE-2021-33847

Description

Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper buffer restrictions in Intel Bluetooth firmware before 22.120 allow authenticated local users to escalate privileges.

Vulnerability

An improper buffer restrictions vulnerability exists in the firmware of certain Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products prior to version 22.120 [1]. The issue stems from insufficient bounds checking when processing certain inputs, which can lead to a buffer overflow within the firmware's memory space. This affects a range of Intel Bluetooth adapters and Killer networking products that share the same firmware base.

Exploitation

To exploit this vulnerability, an attacker must have local access to the system and be authenticated as a user. The attacker can then send specially crafted Bluetooth commands or data to the affected firmware, triggering the buffer overflow. No additional privileges or user interaction beyond authentication are required, and the attack can be carried out from a standard user context.

Impact

Successful exploitation allows the attacker to escalate their privileges on the local system. The buffer overflow can be leveraged to execute arbitrary code within the firmware context, potentially gaining elevated privileges such as SYSTEM or kernel-level access. This compromises the confidentiality, integrity, and availability of the system.

Mitigation

Intel has released firmware version 22.120 to address this vulnerability [1]. Users should update their Bluetooth firmware to this version or later through the vendor's update mechanisms (e.g., Intel Driver & Support Assistant or device manufacturer updates). No workarounds are available for unpatched versions. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

References
  1. INTEL-SA-00628

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.