CVE-2025-20054
published 2025-05-13CVE-2025-20054: Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via…
PriorityP419medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.14%
3.9th percentile
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250512.1~deb12u1 (bookworm) | intel-microcode 3.20250512.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-05-27·CVSS 5.7
CVE-2024-28956 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2025-20012,
CVE-2025-24495)
Michal Raviv
OSV
CVE-2025-20054: Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of servi
osv·2025-05-13·CVSS 6.8
CVE-2025-20054 [MEDIUM] CVE-2025-20054: Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of servi
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
GHSA
GHSA-c97h-mp76-mj2r: Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of servi
ghsa_unreviewed·2025-05-13
CVE-2025-20054 [MEDIUM] CWE-248 GHSA-c97h-mp76-mj2r: Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of servi
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-05-27·CVSS 5.6
CVE-2024-45332 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtai
Red Hat
microcode_ctl: Uncaught exception in the core management mechanism
vendor_redhat·2025-05-13·CVSS 6.8
CVE-2025-20054 [MEDIUM] CWE-248 microcode_ctl: Uncaught exception in the core management mechanism
microcode_ctl: Uncaught exception in the core management mechanism
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 8) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 9) - Fix deferred
Debian
CVE-2025-20054: intel-microcode - Uncaught exception in the core management mechanism for some Intel(R) Processors...
vendor_debian·2025·CVSS 6.8
CVE-2025-20054 [MEDIUM] CVE-2025-20054: intel-microcode - Uncaught exception in the core management mechanism for some Intel(R) Processors...
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
trixie: resolved (fixed in 3.20250512.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-13
Published