Intel has released software and firmware updates to address a number of vulnerabilities in its devices. Last week, the manufacturer published 22 security advisories, seven of which were rated as high risk. These advisories describe 18 critical vulnerabilities, most of which can be exploited to gain elevated privileges. Some vulnerabilities could lead to data disclosure or denial of service (DoS). Most of the issues require local access to the device to be exploited.

One of the advisories indicates that the BIOS of some Intel processors is vulnerable to 10 high-risk vulnerabilities that allow attackers to elevate privileges. Another advisory reports a serious vulnerability in Intel chipset firmware affecting Server Platform Services (SPS), Power Management Controller (PMC), and Active Management Technology (AMT).

High severity vulnerabilities were also identified in the following components: Kernelflinger, Intel Quartus Prime components, PROSet/Wireless Wi-Fi and Killer Wi-Fi devices, as well as AMT SDK, Setup and Configuration Software (SCS), and Management Engine BIOS eXtensions (MEBx). The remaining warnings concern more than a dozen medium- and low-risk vulnerabilities, which the company also fixed this month.

Some computer manufacturers, such as HPE, have also notified their customers about the Intel vulnerabilities that have been discovered. Given the widespread use of Intel devices and software, these vulnerabilities may be of interest to attackers. However, the CISA’s Catalog of Known Exploited Vulnerabilities for the past 10 years lists only one Intel vulnerability (CVE-2017-5689) out of more than 370 cases of vulnerabilities being exploited in attacks.

Last year, Intel fixed 226 vulnerabilities, and its bug bounty program has paid out an average of $800,000 per year since its launch in 2018. In 2021, two vulnerabilities were rated “critical” and 52 were rated “high risk.”