VYPR
Unrated severityNVD Advisory· Published May 12, 2022· Updated May 5, 2025

CVE-2022-21237

CVE-2022-21237

Description

Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer access flaw in Intel NUC firmware lets a privileged local attacker escalate privileges.

Vulnerability

An improper buffer access vulnerability exists in the firmware for some Intel(R) NUC (Next Unit of Computing) kits and mini PCs. The issue resides in the system firmware and can be triggered by a privileged user with local access. Affected products include multiple Intel NUC models; the advisory INTEL-SA-00654 [1] provides a full list of affected versions and the fixed firmware versions.

Exploitation

An attacker must have local, privileged access to the target system (e.g., administrator or kernel-level access). No network-based exploitation is described. The attacker can exploit the improper buffer access by executing specially crafted inputs or operations that trigger the firmware vulnerability, leading to a buffer handling error.

Impact

Successful exploitation allows a privileged attacker to escalate their privileges further, potentially gaining higher-level system control or bypassing security mechanisms within the firmware or operating system. The impact is limited to privilege escalation (elevation of privilege) with a high severity rating (CVSS v3 base score 8.2 High) as per Intel's advisory [1].

Mitigation

Intel has released firmware updates to address this vulnerability. Users should update the BIOS/firmware on affected Intel NUC devices to the versions specified in INTEL-SA-00654 [1]. No workarounds are provided; the fix is the only mitigation. If a device is end-of-life (EOL), Intel recommends replacing it. The advisory was published on 2022-05-10.

References
  1. INTEL-SA-00654

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Intel/Intel NUCsdescription
  • Intel/NUCllm-fuzzy

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.