CVE-2025-24307
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-26
Assigner: Intel Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| intel | computing_improvement_program | to 2.4.11001 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves improper privilege management in certain Intel(R) CIP software versions before WIN_DCA_2.4.0.11001. It allows an authenticated but unprivileged user to potentially escalate their privileges through a complex attack, possibly via network access, without requiring user interaction or special internal knowledge. The vulnerability mainly affects the integrity of the system with low impact and does not affect confidentiality or availability significantly.
How can this vulnerability impact me? :
The vulnerability may allow an attacker with some level of access to escalate privileges and manipulate data, impacting the integrity of the system at a low level. However, it does not significantly affect confidentiality or availability, so the overall impact is limited but could still lead to unauthorized data manipulation.