CVE-2022-32579 is an improper initialization vulnerability in the firmware of specific Intel NUC Laptop Kits (BC0076 and earlier). A privileged user with physical access could exploit this to escalate privileges. With a CVSS score of 7.2 (HIGH), exploitation requires physical access and high privileges, but once achieved, it can lead to high impact on confidentiality, integrity, and availability. There is no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, indicating no active exploitation. While there is some community discussion and media coverage, it is not considered a widespread or actively exploited threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< bc0076CPE matchmatch criteria | cpe:2.3:o:intel:lapbc510_firmware:*:*:*:*:*:*:*:* | ||
< bc0076CPE matchmatch criteria | cpe:2.3:o:intel:lapbc710_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.