Improper Link Resolution in Intel Server Configuration Utility and Firmware Update Software
CVE-2025-24918

5.4MEDIUM

What is CVE-2025-24918?

The vulnerability arises from improper link resolution prior to file access in certain Intel Server software, which could allow an authenticated attacker to escalate privileges. Exploitation of this flaw requires a high complexity attack and user interaction, compromising system confidentiality, integrity, and availability. This vulnerability impacts the vulnerable systems significantly, necessitating immediate attention and remediation.

Affected Version(s)

Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12.

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.