Improper Initialization in UEFI Firmware in Intel Processors
CVE-2024-31157

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

The UEFI firmware OutOfBandXML module in certain Intel processors is affected by an improper initialization issue. This vulnerability could allow a privileged user with local access to exploit the firmware, leading to potential information disclosure. Stakeholders are recommended to evaluate their systems and implement necessary mitigations as provided in the corresponding Intel advisory.

Affected Version(s)

Intel(R) Processors See references

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.