Privilege Escalation Vulnerability in Intel CIP Software
CVE-2025-24848
5.4MEDIUM
What is CVE-2025-24848?
A vulnerability exists in some Intel CIP software prior to version WIN_DCA_2.4.0.11001 due to a failure in the protection mechanism within Ring 3, affecting user applications. An attacker could exploit this flaw to escalate privileges, leveraging unprivileged software access combined with a privileged user's permissions. Successful exploitation could require local access under certain conditions, without needing specific insider knowledge, and may involve passive user interaction. This vulnerability poses risks to the confidentiality, integrity, and availability of the affected systems.
Affected Version(s)
Intel(R) CIP software before version WIN_DCA_2.4.0.11001