CVE-2025-24862
Intel Computing Improvement Program vulnerability analysis and mitigation

Overview

CVE-2025-24862 is an unrestricted file upload vulnerability (CWE-434) in Intel Computing Improvement Program (CIP) software affecting versions prior to WIN_DCA_2.4.0.11001. The flaw resides within Ring 3 (User Applications) and may allow an escalation of privilege under specific conditions. It was published on November 11, 2025, with a patch released shortly after. The vulnerability carries a CVSS v3.1 base score of 2.0 (Low) and a CVSS v4.0 base score of 2.0 (Low), reflecting the high attack complexity and privilege requirements involved (Intel Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) and exists within the Ring 3 user application layer of Intel CIP software. Exploitation requires a network-based attack vector with high complexity, high privileges, the presence of specific attack requirements (such as special internal knowledge), and passive user interaction from a privileged user. An unprivileged software adversary, in combination with a privileged user, could potentially upload a dangerous file type to manipulate data integrity. No public technical write-ups or proof-of-concept code have been identified (Intel Advisory, Red Hat CVE).

Impact

Successful exploitation results in a low impact to the integrity of the vulnerable system, with no impact on confidentiality or availability. The attack scenario involves potential data manipulation by an unprivileged attacker leveraging a privileged user's interaction, but the scope remains unchanged and subsequent system impacts on confidentiality, integrity, and availability are all rated as none. The limited impact scope and stringent preconditions significantly constrain the real-world risk of this vulnerability (Intel Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-24862. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. The high attack complexity, requirement for privileged access, and need for passive user interaction further reduce the likelihood of weaponization (Red Hat CVE, Intel Advisory).

Mitigation and workarounds

Intel has released a patched version of the Computing Improvement Program software: WIN_DCA_2.4.0.11001. Users should upgrade to this version or later as the primary remediation step. Additional hardening measures include restricting file upload permissions within the application, implementing strict file type validation, monitoring and limiting user privileges, and reviewing network access controls to the affected application (Intel Advisory).

Additional resources


SourceThis report was generated using AI

Related Intel Computing Improvement Program vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24838HIGH7.7
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24863MEDIUM6
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24847MEDIUM5.7
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24848MEDIUM5.4
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025
CVE-2025-24862LOW2
  • Intel Computing Improvement Program logoIntel Computing Improvement Program
  • cpe:2.3:a:intel:computing_improvement_program
NoYesNov 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management