CVE-2025-20005 is a medium-severity vulnerability (CVSS 5.6) affecting some Intel reference platform UEFI firmware, caused by improper buffer restrictions that could allow an escalation of privilege and data manipulation. Exploitation requires local access by a privileged user and involves a high complexity attack, primarily impacting system integrity. While it has a high integrity impact, there is no known public exploit code, nor is it listed on CISA's Known Exploited Vulnerabilities catalog. Community discussion and media coverage are currently absent, and its EPSS score is very low, indicating minimal current risk or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Intel(R) Reference Platforms May Allow An Escalation Of Privilege. System Software Adversary With A Privileged User Combined With A High Complexity Attack May Enable Data Manipulation. This Result May Potentially Occur Via Local Access When Attack Requirements Are Not Present Without Special Internal Knowledge And Requires No User Interaction. The Potential Vulnerability May Impact The Confidentiality (None), Integrity (High) And Availability (Low) Of The Vulnerable System, Resulting In Subsequent System Confidentiality (None), Integrity (None) And Availability (None) Impacts. | See referencesCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.