Insufficient Granularity of Access Control
CVE-2025-22839
Summary
Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- HIGH
- ADJACENT_NETWORK
- HIGH
- CHANGED
- NONE
- HIGH
- HIGH
- LOW
CWE-1220 - Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
References
Advisory Timeline
- Published