Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CVSS Details
- CVSS 4.0 Base Score: 6.8 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade microcode_ctl | Jul 4, 2025 | Feb 12, 2025 |
| Debian | — | Upgrade intel-microcode | Mar 17, 2025 | Feb 12, 2025 |
| Dell Poweredge Dsa2025041 | — | Upgrade Dell PowerEdge to the latest version | Oct 23, 2025 | Feb 11, 2025 |
| Oracle_linux | — | Upgrade microcode_ctl | May 26, 2025 | Feb 12, 2025 |
| Redhat_linux | — | No solution existsUpgrade microcode_ctl | May 14, 2025 | Feb 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub