Potential Privileged User Enabled Denial of Service Vulnerability in UEFI Firmware
CVE-2023-25546

2.5LOW

Key Information:

Vendor
Intel
Vendor
CVE Published:
16 September 2024

Summary

An out-of-bounds read vulnerability exists in the UEFI firmware for specific Intel(R) processors. This flaw can potentially be exploited by a privileged user with local access, enabling them to cause a denial of service condition. Affected users and organizations should apply security patches and mitigations described in the Intel security advisory to protect their systems against potential exploits.

Affected Version(s)

UEFI firmware for some Intel(R) Processors See references

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.