← Vulnerability feed

Vulnerability record · CVE-2021-33060 · published 18 August 2022

CVE-2021-33060: Intel xeon gold 5315y firmware out-of-bounds write vulnerability

Intel · Xeon Gold 5315y Firmware

Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

7.8 CVSS 3.1 High EPSS 0.26% · top 83.6% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
72Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

72 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33060 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2021-0187Intel xeon gold 6342 firmware vulnerabilityImproper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privileg…EPSS 0.21%7.8CVE-2021-0159Intel xeon bronze 3204 firmware improper input validation vulnerabilityImproper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescal…EPSS 0.27%7.0CVE-2022-26837Intel xeon gold 5317 firmware improper input validation vulnerabilityImproper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege…EPSS 0.22%6.8CVE-2022-21216Intel xeon gold 5315y firmware vulnerabilityInsufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged …EPSS 0.54%6.7CVE-2022-41804Debian linux vulnerabilityUnauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable e…EPSS 0.27%6.7CVE-2022-33196Intel xeon gold 5315y firmware incorrect default permissions vulnerabilityIncorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extens…EPSS 0.21%6.7CVE-2022-32231Intel xeon gold 6138p firmware vulnerabilityImproper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege v…EPSS 0.21%6.7CVE-2022-30539Intel xeon gold 5315y firmware use after free vulnerabilityUse after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local …EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2021-33060), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.