Privilege Escalation Vulnerability in Intel One Boot Flash Update Software
CVE-2025-25059

5.4MEDIUM

What is CVE-2025-25059?

The Intel One Boot Flash Update software prior to version 14.1.31 is prone to an uncontrolled search path vulnerability that may allow an unauthorized user to escalate privileges. This vulnerability can be exploited by an adversary with an authenticated user account by leveraging a complex series of actions, requiring local access and user interaction. Successful exploitation of this issue may compromise the confidentiality, integrity, and availability of the affected system, underscoring the need for immediate attention to secure installations.

Affected Version(s)

Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.