Privilege Escalation Risk in Intel Processor Identification Utility
CVE-2025-27246

5.4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-27246?

The Intel Processor Identification Utility suffers from incorrect default permissions, allowing potential escalation of privileges. This vulnerability can be exploited by an authenticated user through a complex attack that requires local access and active interaction. When exploited, it may lead to local code execution, significantly impacting the system's confidentiality, integrity, and availability. Users should apply the recommended updates to safeguard against this vulnerability.

Affected Version(s)

Intel(R) Processor Identification Utility before version 8.0.43

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.