CVE-2025-22839Insufficient Granularity of Access Control in Intel-microcode

Severity
7.3HIGHNVD
OSV7.0
EPSS
0.0%
top 93.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateNov 10

Description

Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.

CVSS vector

CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20250812.1~deb12u1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2025-11-10
OSV
CVE-2025-22839: Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially e2025-08-12
GHSA
GHSA-43pp-4q99-jfhm: Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially e2025-08-12

📋Vendor Advisories

2
Ubuntu
Intel Microcode vulnerabilities2025-11-10
Debian
CVE-2025-22839: intel-microcode - Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon...2025