CVE-2022-37336
Description
Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper input validation in Intel NUC BIOS firmware allows a privileged local attacker to escalate privileges.
Vulnerability
Improper input validation in the BIOS firmware for certain Intel(R) NUC products may allow a privileged user to potentially enable escalation of privilege via local access [1]. Affected versions include Intel NUC 8 Rugged, Intel NUC 8 Pro, Intel NUC 8 Mainstream-G, Intel NUC 8 Pro Kit/Board, and Intel NUC 8 Miniature PCs running BIOS firmware versions prior to updates specified in INTEL-SA-00892 [1].
Exploitation
An attacker must already have privileged access to the system (local access) to exploit this vulnerability [1]. The exploitation requires the attacker to send specially crafted input to the BIOS firmware, which due to improper input validation, triggers the escalation path [1].
Impact
Successful exploitation allows the attacker to escalate their privileges on the affected system [1]. The exact privilege level gained is not specified in the available reference, but the vulnerability is classified as high severity with a CVSS base score of 8.2, indicating significant impact on confidentiality, integrity, and availability [1].
Mitigation
Intel released firmware updates to address this vulnerability; affected users should update their BIOS to the fixed versions listed in the advisory INTEL-SA-00892 [1]. No workaround is mentioned in the reference, and the product may be affected if the BIOS is not updated.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Intel/NUC BIOS firmwaredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.