VYPR
Unrated severityNVD Advisory· Published Nov 14, 2023· Updated Feb 13, 2025

CVE-2023-22329

CVE-2023-22329

Description

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper input validation in BIOS firmware for some Intel processors lets an authenticated user cause denial of service via adjacent network access.

Vulnerability

An improper input validation vulnerability exists in the BIOS firmware for certain Intel(R) processors. The issue affects firmware versions prior to the updates released under Intel-SA-00924 [1]. The vulnerability resides in the input validation routines within the BIOS, where insufficient checks allow malformed inputs to trigger an unstable state. The exact affected processor models and firmware versions are detailed in the Intel security advisory [1].

Exploitation

An authenticated user can exploit this vulnerability by sending specially crafted input over adjacent network access. The attacker must have either local administrative access or authenticated network access to the target system, as described in the advisory [1]. The exploitation sequence involves delivering malformed data to the vulnerable BIOS input path, which triggers the denial of service condition [1].

Impact

Successful exploitation leads to a denial of service scenario where the system becomes unresponsive or crashes, requiring a power cycle to recover. The impact is limited to availability, with no indication of data compromise or privilege escalation [1].

Mitigation

Intel has released firmware updates to address this vulnerability, as documented in Intel-SA-00924 [1]. Users should apply the updated BIOS/firmware from their system manufacturer. No workarounds are provided apart from the firmware update [1].

References
  1. INTEL-SA-00924

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.