CVE-2022-36789
Description
Improper access control in BIOS firmware on certain Intel NUC 10 devices allows a privileged local user to escalate privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper access control in BIOS firmware on certain Intel NUC 10 devices allows a privileged local user to escalate privilege.
Vulnerability
A vulnerability exists in the BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs. The issue is caused by improper access control, which allows a privileged user to bypass security restrictions. Affected versions are those before firmware version FNCML357.0053, as detailed in Intel security advisory INTEL-SA-00752 [1].
Exploitation
An attacker must have privileged access to the system, such as administrative rights, and local physical or interactive access. The exploitation requires the attacker to modify firmware settings or perform actions that leverage the improper access control, potentially by using system management mode or other privileged interfaces [1].
Impact
Successful exploitation could allow the attacker to escalate privileges further, potentially gaining higher levels of control over the system, including the ability to execute arbitrary code at the firmware level or bypass security features [1].
Mitigation
Intel has released firmware version FNCML357.0053 to address this vulnerability. Users should update their BIOS/firmware to this version or later. Intel also recommends following general security practices to limit local access for untrusted users [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Intel/NUC 10 Performance Kits and NUC 10 Performance Mini PCsdescription
- Range: < FNCML357.0053
- Range: < FNCML357.0053
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.