External Control of File Name in Intel CIP Software
CVE-2025-20614

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-20614?

A vulnerability exists in Intel's CIP software that allows external control of file names or paths within certain user applications. This flaw enables unprivileged software adversaries to exploit privileges of a legitimate user, leading to potential privilege escalation. The attack can be executed locally without requiring intricate internal knowledge or interaction from the user, making it particularly dangerous. Users of the affected versions should assess their systems for potential exposure, ensuring that appropriate security measures are in place to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Intel(R) CIP software before version WIN_DCA_2.4.0.11001

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.