Intel has disclosed two high-severity vulnerabilities affecting a wide range of Intel processor families, allowing threat actors and malicious software to gain higher privilege levels on the device.
See also: The upcoming Intel Core i5-12400F looks to have strong performance

See also: Mac apps and Intel: Affected by application memory bug
The flaws were discovered by SentinelOne and are tracked as CVE-2021-0157 and CVE-2021-0158, and both have a CVSS v3 score of 8,2 (high).
The first concerns inadequate control flow management in the BIOS firmware for certain Intel processors, while the second is based on improper input validation in the same component.
These vulnerabilities could lead to privilege escalation on the machine, but only if the attacker had physical access to vulnerable devices.
The products affected, according to Intel, are as follows:
- Intel Xeon Processor E Family
- Intel Xeon Processor E3 v6 Family
- Intel Xeon Processor W Family
- 3rd Generation Intel Xeon Scalable Processors
- 11th Generation Intel Core Processors
- 10th Generation Intel Core Processors
- 7th Generation Intel Core Processors
- Intel Core X-series Processors
- Intel Celeron Processor N Series
- Intel Pentium Silver Processor Series
Intel has not disclosed many technical details about these two vulnerabilities, but advises users to remediate the flaws by applying the available BIOS updates.
This is particularly problematic because motherboard vendors do not release BIOS updates frequently and do not support their products with security updates for a long period of time.
See also: Intel CEO vows to "challenge" Nvidia
Taking into account that the Intel Core 7th generation processors were released five years ago, it is doubtful that MB manufacturers continue to release security BIOS updates for them.
Therefore, some users will have no practical way to fix the above flaws. In such cases, we would recommend setting a strong password to access the BIOS settings.
A third vulnerability affects cars
A third vulnerability for which Intel released a separate advisory on the same day is CVE-2021-0146, a high‑severity privilege‑escalation vulnerability (CVSS 7.2).
This flaw affects the following products:

Intel released a firmware update to mitigate this flaw and users will receive it via code updates provided by the system manufacturer.
Positive Technologies, which discovered and reported the flaw to Intel, says that the defect could allow threat actors to gain access to extremely sensitive information.
Positive Technologies says that the flaw also affects many car models that use the Intel Atom E3900, including the Tesla Model 3.
Users should apply a BIOS update from the device vendor to address this flaw, so regularly check your manufacturer’s website.
Information source: bleepingcomputer.com
