Privilege Escalation Vulnerability in Intel One Boot Flash Update Software
CVE-2025-27711

5.4MEDIUM

What is CVE-2025-27711?

The Intel One Boot Flash Update software has a vulnerability due to incorrect default permissions in its user applications. This flaw can allow an unprivileged attacker, who has authenticated access, to execute a complex attack that may lead to privilege escalation. The attack can potentially be carried out locally under specific conditions, necessitating active user interaction. This vulnerability poses risks to the system's confidentiality, integrity, and availability, potentially allowing unauthorized access to sensitive information.

Affected Version(s)

Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.