Improper Input Validation in UEFI Firmware for Intel Processors
CVE-2023-43758

8.7HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

An improper input validation issue in the UEFI firmware for several Intel processors may enable a local privileged user to escalate privileges. This vulnerability poses a potential security risk, allowing unauthorized access to elevated privileges, which could lead to further exploitation of the system. It is critical for users and administrators to review the affected systems and apply necessary mitigations as outlined in the Intel security advisory.

Affected Version(s)

Intel(R) processors See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.