VYPR
Unrated severityNVD Advisory· Published Aug 11, 2023· Updated Oct 2, 2024

CVE-2023-27887

CVE-2023-27887

Description

Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper initialization in Intel NUC BIOS firmware allows a privileged local attacker to disclose sensitive information.

Vulnerability

Improper initialization in the BIOS firmware for some Intel NUCs, as described in INTEL-SA-00892 [1], may allow a privileged user to access sensitive information. The issue stems from an initialization flaw in the BIOS that could leak data to an attacker with local access and elevated privileges. Affected products include specific Intel NUC models with BIOS versions prior to the fixed release [1].

Exploitation

To exploit this vulnerability, an attacker must have local access to the system and possess elevated privileges, such as administrator or SYSTEM-level access. The attacker would need to execute a specially crafted program or tool that triggers the BIOS initialization flaw, leading to the disclosure of sensitive information [1]. No user interaction beyond the attacker's own actions is required.

Impact

Successful exploitation could allow an attacker with local, privileged access to read sensitive information from the BIOS or system memory. This includes potential disclosure of cryptographic keys, passwords, or other confidential data stored in firmware. The impact is limited to information disclosure; no code execution or denial of service is indicated [1].

Mitigation

Intel has released BIOS updates to address this vulnerability. Affected users should update to the fixed BIOS version provided by Intel for their specific NUC model [1]. As of the publication date, no workarounds are available; the recommended mitigation is to apply the latest BIOS update from Intel.

References
  1. INTEL-SA-00892

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Intel/NUCs BIOS firmwaredescription
  • Intel/NUCllm-fuzzy

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.