Rewterz
Rewterz Threat Advisory – Multiple Intel NUC BIOS and NUC BIOS Firmware Vulnerabilities
January 12, 2024
Rewterz
Rewterz Threat Alert – New Version of Atomic Stealer Uses Encrypted Payload to Target MacOS Users – Active IOCs
January 12, 2024

Rewterz Threat Advisory – Multiple Intel Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-32544 CVSS: 7.3

Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element is vulnerable to a denial of service, caused by improper access control. A local authenticated attacker could exploit this vulnerability to cause a denial of service.

CVE-2023-29244 CVSS: 6.7

Intel Integrated Sensor Hub driver for Windows 10 for Intel NUC P14E Laptop Element could allow a local authenticated attacker to gain elevated privileges on the system, caused by incorrect default permissions. An attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2023-38541 CVSS: 6.7

Intel HID Event Filter drivers for Windows 10 for Intel NUC laptops could allow a local authenticated attacker to gain elevated privileges on the system, caused by insecure inherited permissions. An attacker could exploit this vulnerability to gain elevated privileges on the system.

CVE-2023-32272 CVSS: 7.9

Intel NUC Pro Software Suite Configuration Tool is vulnerable to a denial of service, caused by an uncontrolled search path element. A local authenticated attacker could exploit this vulnerability to cause a denial of service.

Impact

  • Denial of Service
  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2023-32544
  • CVE-2023-29244
  • CVE-2023-38541
  • CVE-2023-32272

Affected Vendors

Intel

Affected Products

  • Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element 1.1.44
  • Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element 1.1.43
  • Intel Integrated Sensor Hub driver for Windows 10 for Intel NUC P14E Laptop Element 5.4.1.4478
  • Intel Integrated Sensor Hub driver for Windows 10 for Intel NUC P14E Laptop Element 5.4.1.4477
  • Intel HID Event Filter drivers for Windows 10 for Intel NUC laptops 2.2.2.0
  • Intel HID Event Filter drivers for Windows 10 for Intel NUC laptops 2.2.1.9
  • Intel NUC Pro Software Suite Configuration Tool 3.0.0.5
  • Intel NUC Pro Software Suite Configuration Tool 3.0.0.4

Remediation

Refer to INTEL Security Advisory for patch, upgrade or suggested workaround information.

INTEL Security Advisory