Privilege Escalation Vulnerability in Intel Server Firmware
CVE-2025-20082

8.7HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
13 May 2025

What is CVE-2025-20082?

A race condition in the UEFI firmware's SmiVariable driver for specific Intel Server boards can be exploited by a privileged user with local access. This vulnerability may lead to the enablement of unauthorized privilege escalation, compromising the integrity of the system operation.

Affected Version(s)

Intel(R) Server D50DNP and M50FCP boards See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.