CVE-2025-24307: Low severity Intel CIP software vulnerability
Improper privilege management for some Intel(R) CIP software before version WINDCA2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data manipulation. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24307?
CVE-2025-24307 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-24307?
To mitigate CVE-2025-24307, update your Intel CIP software to version WIN_DCA_2.4.0.11001 or later.
What kind of attack does CVE-2025-24307 allow?
CVE-2025-24307 allows an unprivileged software adversary to carry out a high complexity attack that can lead to privilege escalation.
Who is affected by CVE-2025-24307?
CVE-2025-24307 affects users of Intel CIP software versions prior to WIN_DCA_2.4.0.11001.
What are the implications of CVE-2025-24307 for users?
The implications of CVE-2025-24307 include potential unauthorized data manipulation by an authenticated attacker.