CVE-2025-24847
Intel Computing Improvement Program vulnerability analysis and mitigation

Overview

CVE-2025-24847 is an improper input validation vulnerability in Intel Computing Improvement Program (CIP) software affecting versions before WIN_DCA_2.4.0.11001, operating within Ring 3 (User Applications). The vulnerability can lead to information disclosure when exploited by an unprivileged adversary in conjunction with a privileged user account. It was published on November 11, 2025, with a patch made available on November 26, 2025. The vulnerability carries a CVSS v3.1 base score of 4.5 (Medium) and a CVSS v4.0 base score of 5.7 (Medium) (Intel Advisory, Red Hat CVE).

Technical details

The root cause is improper input validation (CWE-20) within the Ring 3 user application layer of Intel CIP software. An attacker with network access can exploit this flaw by leveraging a privileged user account in a low-complexity attack that requires passive user interaction. The attack vector is network-based, with attack requirements present (CVSS v4.0 AT:P), meaning specific preconditions must be met for exploitation to succeed. No special internal knowledge of the target system is required beyond the privileged user context (Intel Advisory, Red Hat CVE).

Impact

Successful exploitation results in a high confidentiality impact on the vulnerable system, with no impact to integrity or availability. Sensitive data from the affected Intel CIP installation may be exposed to an adversary via network access. The scope is limited to the vulnerable system itself, with no downstream or lateral impact to subsequent systems indicated (Intel Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, reflecting a very low probability of exploitation in the near term (Red Hat CVE, Intel Advisory).

Mitigation and workarounds

Intel recommends upgrading the Intel Computing Improvement Program (CIP) software to version WIN_DCA_2.4.0.11001 or later, which addresses the improper input validation flaw. As interim measures, organizations should limit network access for privileged users running Intel CIP, implement strict user interaction controls, and monitor for unauthorized information disclosure. Regular security audits of user applications are also advised (Intel Advisory).

Additional resources


SourceThis report was generated using AI

Related Intel Computing Improvement Program vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24838HIGH7.7
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24863MEDIUM6
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24847MEDIUM5.7
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24848MEDIUM5.4
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24862LOW2
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management