Intel
Intel Uefi Firmware: vulnerabilidades y CVE
Intel Uefi Firmware tiene 34 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses8
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54334 | Crítica (9.8) | 0.80% | — | 14 sept 2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from… |
| CVE-2026-54333 | Crítica (9.8) | 0.80% | — | 14 sept 2026 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that… |
| CVE-2026-20712 | Media (4) | 0.12% | — | 11 ago 2026 | Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may… |
| CVE-2025-35991 | Media (5.6) | 0.10% | — | 12 may 2026 | Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity… |
| CVE-2025-20105 | Alta (8.7) | 0.13% | — | 10 mar 2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity… |
| CVE-2025-20096 | Media (5.9) | 0.14% | — | 10 mar 2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable… |
| CVE-2025-20005 | Media (5.7) | 0.10% | — | 10 mar 2026 | Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may… |
| CVE-2025-11577 | Alta (7.6) | 0.26% | — | 14 oct 2025 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to… |
| CVE-2024-39279 | Media (6.8) | 0.22% | — | 12 feb 2025 | Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access. |
| CVE-2024-31157 | Media (6.8) | 0.23% | — | 12 feb 2025 | Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. |
| CVE-2024-31155 | Alta (8.7) | 0.19% | — | 12 feb 2025 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-29214 | Alta (8.7) | 0.25% | — | 12 feb 2025 | Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-28127 | Alta (8.7) | 0.25% | — | 12 feb 2025 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-28047 | Media (6.8) | 0.25% | — | 12 feb 2025 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. |
| CVE-2024-24582 | Alta (8.7) | 0.25% | — | 12 feb 2025 | Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-21859 | Media (6.8) | 0.20% | — | 12 feb 2025 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. |
| CVE-2023-43758 | Alta (8.7) | 0.28% | — | 12 feb 2025 | Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2023-34440 | Alta (8.7) | 0.25% | — | 12 feb 2025 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-25565 | Media (4.8) | 0.18% | — | 13 nov 2024 | Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access. |
| CVE-2024-21871 | Alta (7.3) | 0.19% | — | 16 sept 2024 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-21829 | Alta (8.7) | 0.16% | — | 16 sept 2024 | Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-21781 | Alta (7) | 0.17% | — | 16 sept 2024 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access. |
| CVE-2023-43626 | Alta (8.7) | 0.14% | — | 16 sept 2024 | Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2023-42772 | Alta (8.7) | 0.17% | — | 16 sept 2024 | Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2023-41833 | Alta (8.7) | 0.12% | — | 16 sept 2024 | A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2023-25546 | Baja (1.8) | 0.14% | — | 16 sept 2024 | Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access. |
| CVE-2023-23904 | Media (6.9) | 0.14% | — | 16 sept 2024 | NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2023-22351 | Media (6.9) | 0.14% | — | 16 sept 2024 | Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2024-22095 | Alta (7.2) | 0.18% | — | 16 may 2024 | Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access. |
| CVE-2022-46329 | Media (6.7) | 0.28% | — | 11 ago 2023 | Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Intel
Graphics Driver · 73Active Management Technology Firmware · 54Proset/wireless Wifi · 52Quartus Prime · 44Converged Security Management Engine Firmware · 44Graphics Drivers · 43Core I7-10710u Firmware · 43Core I7-8665u Firmware · 42Core I9-9900k Firmware · 42Core I7-10510y Firmware · 42Core I7-10510u Firmware · 42Core I9-9880h Firmware · 41