CVE-2025-20037: Race Condition
Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20037?
CVE-2025-20037 is considered a medium severity vulnerability due to its potential for privilege escalation by a local user.
How do I fix CVE-2025-20037?
To fix CVE-2025-20037, update the Intel Converged Security and Management Engine firmware to the latest version provided by Intel.
Who is affected by CVE-2025-20037?
CVE-2025-20037 affects systems running specific versions of Intel Converged Security and Management Engine firmware.
What is a time-of-check time-of-use race condition as described in CVE-2025-20037?
A time-of-check time-of-use race condition occurs when a system checks conditions of use but does not properly manage changes before execution, potentially allowing privilege escalation.
Can CVE-2025-20037 be exploited remotely?
CVE-2025-20037 requires local access for exploitation, making it less dangerous than vulnerabilities that can be exploited remotely.