CVE-2025-20064 details an improper input validation vulnerability within the UEFI FlashUcAcmSmm module on certain Intel reference platforms, which can lead to an escalation of privilege and local code execution. Rated with a CVSS score of 8.7 (High), this vulnerability requires a privileged user and a high complexity attack via local access, but no user interaction, potentially severely impacting system confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Intel(R) Reference Platforms May Allow An Escalation Of Privilege. System Software Adversary With A Privileged User Combined With A High Complexity Attack May Enable Local Code Execution. This Result May Potentially Occur Via Local Access When Attack Requirements Are Not Present Without Special Internal Knowledge And Requires No User Interaction. The Potential Vulnerability May Impact The Confidentiality (High), Integrity (High) And Availability (High) Of The Vulnerable System, Resulting In Subsequent System Confidentiality (High), Integrity (High) And Availability (High) Impacts. | See referencesCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.