CVE-2024-24582
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
12/02/2025
Last modified:
12/02/2025
Description
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH