CVE-2025-24303

7.8

Intel · 800 Series Ethernet

A privilege escalation vulnerability exists in the Intel 800 Series Ethernet Linux kernel-mode driver due to improper checks for exceptional conditions.

Executive summary

An authenticated local attacker can leverage an improper condition check in the Intel 800 Series Ethernet driver to achieve escalation of privilege.

Vulnerability

This vulnerability, categorized under CWE-754, involves an improper check for unusual or exceptional conditions within the kernel-mode driver. An authenticated user with local access can exploit this flaw to potentially escalate their privileges on the host system.

Business impact

The ability for an authenticated local user to escalate privileges poses a significant risk to system integrity and confidentiality. By gaining elevated access, an attacker could bypass standard security controls, access sensitive data, or install persistent malicious software. With a CVSS score of 7.8, this vulnerability is considered high severity, necessitating prompt remediation to prevent unauthorized administrative control.

Remediation

Immediate Action: Update the Intel 800 Series Ethernet Linux kernel-mode driver to version 1.17.2 or later as specified in the official Intel security advisory.

Proactive Monitoring: Monitor system logs for unusual kernel-level activity or unexpected privilege escalation events, particularly involving local user accounts.

Compensating Controls: Limit local system access to authorized personnel only and ensure that standard user accounts are restricted from executing unnecessary kernel-level operations or sensitive system binaries.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for privilege escalation and the high CVSS severity rating, organizations should prioritize updating the affected Ethernet drivers. Administrators must verify their current driver versions against the 1.17.2 threshold and apply the vendor-provided patch during the next maintenance cycle to mitigate the risk of local exploitation.

More Intel CVEs

Sources