Executive brief
The Intel Server Firmware Update Utility, used to manage and update firmware on server boards, contains a vulnerability that could allow a local user to gain elevated privileges. An attacker with existing access to the system could exploit this flaw to run unauthorized code with higher permissions, potentially compromising the entire server. This requires a complex attack and interaction from a legitimate user to succeed.
Technical details
An uncontrolled search path vulnerability (CWE-427) exists in the Intel Server Firmware Update Utility Software before version 16.0.12 within Ring 3 user applications. A local, authenticated attacker can exploit this by placing a malicious file in a directory searched by the utility, which may then be executed with the utility's higher privileges. The attack is characterized by high complexity, requiring specific environmental conditions and active user interaction to be successful. If exploited, it provides full impact to confidentiality, integrity, and availability (High/High/High) on the local system. Intel has released version 16.0.12 to mitigate this issue.
Affected products
- Intel Server Firmware Update Utility Software before 16.0.12
Timeline
- 2026-05-12: disclosed: Initial advisory release by Intel
- 2026-05-12: patched: Update version 16.0.12 released