CVE-2024-24582
published 2025-02-12CVE-2024-24582: Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of…
PriorityP432high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
EPSS
0.25%
16.3th percentile
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250211.1~deb12u1 (bookworm) | intel-microcode 3.20250211.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5pm-xmgf-pjcq: Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation
ghsa_unreviewed·2025-02-13
CVE-2024-24582 [HIGH] CWE-20 GHSA-g5pm-xmgf-pjcq: Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
OSV
CVE-2024-24582: Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation
osv·2025-02-12·CVSS 8.7
CVE-2024-24582 [HIGH] CVE-2024-24582: Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
Red Hat
microcode_ctl: Improper input validation in XmlCli feature for UEFI firmware
vendor_redhat·2025-02-12·CVSS 8.7
CVE-2024-24582 [HIGH] CWE-20 microcode_ctl: Improper input validation in XmlCli feature for UEFI firmware
microcode_ctl: Improper input validation in XmlCli feature for UEFI firmware
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
An improper input validation flaw was found in the XmlCli feature for UEFI firmware. Some Intel(R) processors may allow a privileged user to enable privilege escalation via local access.
Statement: Red Hat has given this vulnerability the impact rating of Important due to the potential of escalating privileges locally.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Not affected
Debian
CVE-2024-24582: intel-microcode - Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) ...
vendor_debian·2024·CVSS 8.7
CVE-2024-24582 [HIGH] CVE-2024-24582: intel-microcode - Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) ...
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.20250211.1)
trixie: resolved (fixed in 3.20250211.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-12
Published