Privilege Escalation Vulnerability in UEFI Firmware for Intel Processors
CVE-2024-24582

8.7HIGH

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

A vulnerability exists in the XmlCli feature of the UEFI firmware associated with certain Intel processors, which stems from improper input validation. This flaw could allow a privileged user with local access to potentially escalate their privileges, posing a risk of unauthorized access and control over system resources. It is essential for users to apply the recommended updates and mitigations provided by Intel to safeguard against potential exploitation.

Affected Version(s)

Intel(R) processors See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.