Privilege Escalation Vulnerability in Intel Server Firmware Update Utility
CVE-2025-35999
5.4MEDIUM
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2025-35999?
An improper permission assignment issue exists in the System Firmware Update Utility for Intel Server Boards and Intel Server Systems prior to version 16.0.12. This vulnerability allows users with privileged access to escalate their privileges through a low complexity attack that requires only local access and passive user interaction. If exploited, this could compromise the system's confidentiality, integrity, and availability, allowing unauthorized control over critical system resources.
Affected Version(s)
System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Server Systems Based before version 16.0.12.