Improper Input Validation in Intel Software for User Applications
CVE-2025-24299

8.7HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-24299?

The vulnerability originates from improper input validation within specific Intel User Applications software prior to version WIN_DCA_2.4.0.11001. This flaw allows an authenticated, unprivileged adversary to exploit the system. Attackers can potentially escalate their privileges through low-complexity attacks, which may require network access and can be executed without special internal knowledge or user interaction. Consequently, the weakness poses significant risks to the confidentiality, integrity, and availability of affected systems.

Affected Version(s)

Intel(R) CIP software before version WIN_DCA_2.4.0.11001

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24299 : Improper Input Validation in Intel Software for User Applications