Insufficient Access Control in UEFI Firmware on Intel Processors
CVE-2024-39279

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 February 2025

Summary

A vulnerability exists in the UEFI firmware of certain Intel processors due to insufficient granularity in access control mechanisms. This weakness could allow an authenticated user to potentially conduct a local denial-of-service attack. The flaw highlights the need for robust access control measures in firmware systems to prevent unauthorized actions that can impact system availability.

Affected Version(s)

Intel(R) processors See references

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.