Privilege Escalation Risk in Intel Processor Identification Utility
CVE-2025-27246
5.4MEDIUM
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-27246?
The Intel Processor Identification Utility suffers from incorrect default permissions, allowing potential escalation of privileges. This vulnerability can be exploited by an authenticated user through a complex attack that requires local access and active interaction. When exploited, it may lead to local code execution, significantly impacting the system's confidentiality, integrity, and availability. Users should apply the recommended updates to safeguard against this vulnerability.
Affected Version(s)
Intel(R) Processor Identification Utility before version 8.0.43
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved