Information Disclosure Vulnerability in Intel UEFI Firmware
CVE-2024-21859

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

The vulnerability stems from improper buffer restrictions in the UEFI firmware for specific Intel processors. This flaw could potentially allow a privileged user to access sensitive information through local access, heightening the risk of security breaches. Users should ensure they keep their firmware updated and monitor Intel's security advisories for patches and mitigation strategies.

Affected Version(s)

Intel(R) Processors See references

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.