CVE-2025-20010
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-11
Assigner: Intel Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| intel | processor_identification_utility | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1104 | The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves the use of unmaintained third-party components in Intel Processor Identification Utility versions before 8.0.43. It allows an authenticated user with local access and low attack complexity to escalate their privileges on the system without requiring user interaction or special internal knowledge.
How can this vulnerability impact me? :
The vulnerability can lead to escalation of privilege, potentially impacting the confidentiality, integrity, and availability of the vulnerable system at a high level. This means an attacker could gain unauthorized access or control, compromising system security and functionality.