VYPR
Unrated severityNVD Advisory· Published Nov 11, 2022· Updated Feb 5, 2025

CVE-2022-21794

CVE-2022-21794

Description

Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper authentication in BIOS firmware for Intel NUC products allows a privileged local attacker to escalate privileges.

Vulnerability

An improper authentication vulnerability exists in the BIOS firmware of certain Intel NUC Boards, NUC Business, NUC Enthusiast, and NUC Kits prior to version HN0067 [1]. The flaw resides in the firmware's authentication mechanism, which can be bypassed by a local user with existing privileged access to the system.

Exploitation

An attacker must have local access to the affected system and possess privileged user credentials (e.g., administrator or root). The attacker can then exploit the improper authentication to modify BIOS settings or execute code at the firmware level, bypassing intended security checks [1].

Impact

Successful exploitation allows the attacker to escalate their privileges within the firmware environment, potentially gaining persistent control over the system's boot process and bypassing higher-level operating system security controls [1]. This could lead to full compromise of the device.

Mitigation

Intel has released BIOS firmware version HN0067 to address this vulnerability. Users should update their Intel NUC systems to this version or later via the Intel Driver & Support Assistant or by downloading the firmware from the Intel support website [1]. No workarounds are available; updating is the only mitigation.

References
  1. INTEL-SA-00752

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.