Improper Input Validation in Intel Server Firmware Affects D50DNP and M50FCP Boards
CVE-2025-21094

8.7HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
13 May 2025

What is CVE-2025-21094?

The UEFI firmware DXE module for Intel Server D50DNP and M50FCP boards contains a flaw in input validation processes. If exploited by a privileged user with local access, this vulnerability could potentially allow the user to escalate privileges, posing significant security risks to the system. Ensuring rigorous firmware updates and input validation mechanisms is crucial to safeguarding against such attacks. More details can be found in the related advisory.

Affected Version(s)

Intel(R) Server D50DNP and M50FCP boards See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21094 : Improper Input Validation in Intel Server Firmware Affects D50DNP and M50FCP Boards