CVE-2025-24848

medium
Published 2025-11-11 · Modified 2026-04-29
CVSS v3
6.3
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
6.3

Description

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Predictions

Exploit likelihood
63%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@intel.com — https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01328.html

Application impact

VendorProductVersionsFixed
intel intelcomputing_improvement_program{"endExcluding":"2.4.11001"}2.4.11001

References

CWEs

CWE-693

Verify integrity in audit chain (admin only). AS-IS.