Unquoted Search Path or Element in Ethernet Connections Boot Utility - CVE-2025-20015

 

Unquoted Search Path or Element in Ethernet Connections Boot Utility - CVE-2025-20015

Published: May 14, 2025


Vulnerability identifier: #VU109161
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20015
CWE-ID: CWE-428
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to uncontrolled search path element. A local user can gain elevated privileges.


Affected software

Ethernet Connections Boot Utility
ThinkStation P5 Workstation
ThinkStation P520 Workstation
ThinkStation P520c Workstation
ThinkStation P7 Intel Workstation
ThinkStation P720 Workstation
ThinkStation P920 Workstation
Intel Ethernet Connection Driver for Windows 11 (Version 24H2) - ThinkStation P5
Intel(R) Ethernet Connection Driver for Windows 11 IoT (Version 24H2) - ThinkStation P5, P7
Intel(R) Ethernet Connection Driver for Windows 11 (Version 22H2 or Later) - ThinkStation P520, P520C, P720, P920
Intel Ethernet Connection Driver for Windows 11 (Version 24H2) - ThinkStation P7

How to mitigate CVE-2025-20015

Install updates from vendor's website.

Ethernet Connections Boot Utility - update to 29.4
Intel Ethernet Connection Driver for Windows 11 (Version 24H2) - ThinkStation P5 - update to 1.3534.0
Intel(R) Ethernet Connection Driver for Windows 11 IoT (Version 24H2) - ThinkStation P5, P7 - update to 1.3534.0
Intel(R) Ethernet Connection Driver for Windows 11 (Version 22H2 or Later) - ThinkStation P520, P520C, P720, P920 - update to 1.3534.0
Intel Ethernet Connection Driver for Windows 11 (Version 24H2) - ThinkStation P7 - update to 1.3534.0

External References

Related Security Bulletins