
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24848 is a protection mechanism failure vulnerability in Intel Computing Improvement Program (CIP) software affecting versions before WIN_DCA_2.4.0.11001. The flaw exists within Ring 3 (User Applications) and may allow a local attacker to escalate privileges under specific conditions. It was published on November 11, 2025, with a patch released under Intel Security Advisory INTEL-SA-01328. The vulnerability carries a CVSS v3.1 base score of 6.3 (Medium) and a CVSS v4.0 base score of 5.4 (Medium) (Intel Advisory, Red Hat CVE).
The vulnerability is classified as CWE-693 (Protection Mechanism Failure), meaning a security control within the Intel CIP software fails to properly enforce privilege boundaries at the Ring 3 (user application) level. Exploitation requires a high-complexity local attack scenario: the adversary must be an unprivileged software entity operating alongside a privileged user account, and passive user interaction must occur. Specific attack requirements (AT:P) must also be present, making opportunistic exploitation unlikely. No public technical write-ups or proof-of-concept code have been identified (Intel Advisory, Red Hat CVE).
Successful exploitation could result in high-impact compromise of the affected system's confidentiality, integrity, and availability, effectively granting an attacker elevated privileges on the local machine. However, the scope is unchanged, meaning the impact is contained to the vulnerable system itself with no lateral propagation to other systems noted in the advisory. The attack requires both a privileged user context and passive user interaction, limiting the realistic attack surface to targeted scenarios rather than broad exploitation (Intel Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.021%, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity, requirement for privileged user involvement, and need for passive user interaction significantly reduce the likelihood of widespread exploitation (Red Hat CVE, Intel Advisory).
Intel has released a patched version of the Computing Improvement Program software: WIN_DCA_2.4.0.11001 or later. Users and administrators should update to this version immediately via Intel's official download channels or the software's built-in update mechanism. Additionally, organizations should enforce least-privilege principles, restrict local access to systems running Intel CIP, and monitor for unusual privilege escalation activity on affected endpoints (Intel Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."