Input Validation Flaw in Intel System Security Products
CVE-2023-49615
8.7HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 12 February 2025
Summary
An improper input validation vulnerability present in the Intel System Security Report and System Resources Defense firmware can be exploited by a privileged user. This flaw may enable the user to escalate privileges via local access, compromising the security integrity of the affected systems. Ensuring proper input validation and robust security measures is crucial to prevent exploitation of this vulnerability.
Affected Version(s)
Intel(R) System Security Report and System Resources Defense firmware See references
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved