Privileged Access Vulnerability in Intel UEFI Firmware
CVE-2024-28127

8.7HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 February 2025

What is CVE-2024-28127?

A vulnerability in the UEFI firmware for various Intel processors has been identified, allowing a privileged user with local access to bypass certain security mechanisms. This issue arises from improper input validation, which could potentially be exploited to escalate privileges. Intel has acknowledged the problem, emphasizing the importance of securing UEFI firmware to protect against unauthorized access and control.

Affected Version(s)

Intel(R) Processors See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-28127 : Privileged Access Vulnerability in Intel UEFI Firmware