
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24838 is an improper privilege management vulnerability in Intel Computing Improvement Program (CIP) software affecting User Applications within Ring 3. It affects all versions before WIN_DCA_2.4.0.11001 on Windows and allows an authenticated attacker with low privileges to escalate privileges via network access. The vulnerability was published on November 11, 2025, with a patch advisory released by Intel shortly after. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (Intel Advisory, Red Hat CVE).
The vulnerability is classified as CWE-269 (Improper Privilege Management) and resides in the Ring 3 (User Applications) layer of Intel's CIP software. An authenticated attacker with low privileges can exploit improper privilege controls over a network connection without requiring user interaction or special internal knowledge, provided certain attack requirements (AT:P) are present. The attack complexity is low, making it relatively straightforward to exploit once the preconditions are met. No public technical write-ups or proof-of-concept code have been identified at this time (Intel Advisory, Red Hat CVE).
Successful exploitation can result in a complete compromise of the affected system's confidentiality, integrity, and availability. An attacker who escalates privileges could access sensitive data, tamper with system configurations or files, and disrupt service availability — all without requiring user interaction. The scope is limited to the vulnerable system itself (no scope change), but the high impact across all three CIA pillars makes this a significant risk for organizations running affected Intel CIP software (Intel Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin for the week of November 10, 2025. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term (Intel Advisory, CISA Bulletin).
Intel recommends upgrading Intel Computing Improvement Program (CIP) software to version WIN_DCA_2.4.0.11001 or later, which resolves the improper privilege management issue. As interim measures, organizations should restrict network access to systems running the affected software, enforce the principle of least privilege for user accounts, implement strong authentication mechanisms, and monitor for unauthorized privilege escalation attempts (Intel Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."