#VU104075 Improper access control in Intel products - CVE-2024-30211

 

#VU104075 Improper access control in Intel products - CVE-2024-30211

Published: February 19, 2025 / Updated: February 20, 2025


Vulnerability identifier: #VU104075
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-30211
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Intel Management Engine (ME) driver for Windows
Intel Celeron N4000 Processors
Intel Celeron processor J3000/N3000 series
Intel Pentium Processor N4000 Series
Intel Pentium Processor J4000 Series
Intel Atom processor X E3900 series
Intel 600 Series Chipset
Intel W790 chipset
Intel 700 series chipset
Intel Celeron Processor J Series
Celeron processor N series
Intel Atom x6000E series
C740 series chipset
Intel 500 series chipset
Intel C250 Series Chipset
Intel 400 Series Chipset
Intel Pentium Processor Silver Series
10th Generation Intel Core Processors
Celeron processor 4000 series
Pentium Gold processor series (G54XXU)
Intel 300 Series Chipset
Intel C240 Series Chipset
Intel C230 series chipset
Intel 200 Series Chipset
Intel 100 Series Chipset
8th Gen Intel Core processor
Intel C620 Series Chipset
Intel X299 Chipset
Intel C420 Chipset
Intel Pentium processor N5000 series
Intel Pentium processor J5000 series
Intel Pentium Processor J Series
Intel Pentium Processor N Series
Software vendor:
Intel

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and gain elevated privileges on the system.


Remediation

Install updates from vendor's website.

External links