Improper Input Validation in UEFI Firmware for Intel Processors
CVE-2024-28047

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

A vulnerability exists in the UEFI firmware of certain Intel processors due to improper input validation. This flaw could allow a privileged user to exploit the system locally, leading to potential information disclosure. Users are advised to review the security advisory provided by Intel for guidance and updates.

Affected Version(s)

Intel(R) Processors See references

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.