Privilege Escalation Vulnerability in Intel Server Firmware Update Utility
CVE-2025-35999

5.4MEDIUM

What is CVE-2025-35999?

An improper permission assignment issue exists in the System Firmware Update Utility for Intel Server Boards and Intel Server Systems prior to version 16.0.12. This vulnerability allows users with privileged access to escalate their privileges through a low complexity attack that requires only local access and passive user interaction. If exploited, this could compromise the system's confidentiality, integrity, and availability, allowing unauthorized control over critical system resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before version 16.0.12.

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.