CVE-2025-20093

8.2

Intel · 800 Series Ethernet

An improper check for unusual or exceptional conditions in the Linux kernel-mode driver for Intel 800 Series Ethernet allows an authenticated user to achieve local privilege escalation.

Executive summary

Intel 800 Series Ethernet drivers contain a vulnerability that permits authenticated local users to escalate privileges, posing a significant risk to system integrity.

Vulnerability

This vulnerability is caused by an improper check for exceptional conditions within the Linux kernel-mode driver. An authenticated local user with low privileges can trigger this flaw to achieve escalation of privilege.

Business impact

The ability for a local user to escalate privileges constitutes a severe security risk, as it allows attackers to bypass standard access controls and potentially gain full administrative control over the host system. Given the CVSS score of 8.2, this vulnerability is classified as High severity. Successful exploitation could lead to unauthorized data access, the installation of malicious software, or total system compromise, significantly impacting the confidentiality, integrity, and availability of affected infrastructure.

Remediation

Immediate Action: Update the Intel 800 Series Ethernet driver to version 1.17.2 or later as specified in the official Intel security advisory.

Proactive Monitoring: Monitor system logs for unusual kernel-level error messages or unauthorized attempts to access restricted system resources by low-privileged user accounts.

Compensating Controls: Restrict local system access to authorized personnel only and enforce the principle of least privilege to minimize the number of users capable of interacting with the vulnerable kernel driver.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical path for local attackers to gain elevated permissions on systems utilizing Intel 800 Series Ethernet hardware. Administrators should prioritize the deployment of the updated driver to all affected Linux environments to eliminate the escalation vector. Given the potential for full system compromise, patching should be performed during the next maintenance window.

More Intel CVEs

Sources