Insufficient Control Flow Management in Intel Xeon 6 Processor Firmware
CVE-2025-20004
8.5HIGH
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-20004?
An insufficient control flow management vulnerability in the Alias Checking Trusted Module of Intel(R) Xeon(R) 6 processor E-Cores firmware has the potential to enable local privilege escalation for a privileged user. This weakness allows for unauthorized access and manipulation within the firmware, presenting a serious risk to impacted systems. It is crucial for organizations utilizing affected Intel products to evaluate their security posture and apply necessary patches to mitigate these risks.
Affected Version(s)
Intel(R) Xeon(R) 6 processor E-Cores firmware See references
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved