
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24862 is an unrestricted file upload vulnerability (CWE-434) in Intel Computing Improvement Program (CIP) software affecting versions prior to WIN_DCA_2.4.0.11001. The flaw resides within Ring 3 (User Applications) and may allow an escalation of privilege under specific conditions. It was published on November 11, 2025, with a patch released shortly after. The vulnerability carries a CVSS v3.1 base score of 2.0 (Low) and a CVSS v4.0 base score of 2.0 (Low), reflecting the high attack complexity and privilege requirements involved (Intel Advisory, Red Hat CVE).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and exists within the Ring 3 user application layer of Intel CIP software. Exploitation requires a network-based attack vector with high complexity, high privileges, the presence of specific attack requirements (such as special internal knowledge), and passive user interaction from a privileged user. An unprivileged software adversary, in combination with a privileged user, could potentially upload a dangerous file type to manipulate data integrity. No public technical write-ups or proof-of-concept code have been identified (Intel Advisory, Red Hat CVE).
Successful exploitation results in a low impact to the integrity of the vulnerable system, with no impact on confidentiality or availability. The attack scenario involves potential data manipulation by an unprivileged attacker leveraging a privileged user's interaction, but the scope remains unchanged and subsequent system impacts on confidentiality, integrity, and availability are all rated as none. The limited impact scope and stringent preconditions significantly constrain the real-world risk of this vulnerability (Intel Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-24862. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. The high attack complexity, requirement for privileged access, and need for passive user interaction further reduce the likelihood of weaponization (Red Hat CVE, Intel Advisory).
Intel has released a patched version of the Computing Improvement Program software: WIN_DCA_2.4.0.11001. Users should upgrade to this version or later as the primary remediation step. Additional hardening measures include restricting file upload permissions within the application, implementing strict file type validation, monitoring and limiting user privileges, and reviewing network access controls to the affected application (Intel Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."