Improper Input Validation in Intel Server Firmware
CVE-2025-24308

8.7HIGH

Key Information:

Vendor

Intel

Vendor
CVE Published:
13 May 2025

What is CVE-2025-24308?

The vulnerability in the UEFI firmware error handler for Intel's Server D50DNP and M50FCP products can be exploited by a privileged user with local access. This flaw arises due to improper input validation, which may allow the user to escalate privileges, potentially compromising system integrity and security.

Affected Version(s)

Intel(R) Server D50DNP and M50FCP See references

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.