Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0004}

epss

{'score': 0.00031}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.0004}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0005}

epss

{'score': 0.00036}


Wed, 14 May 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Fri, 14 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
Title microcode_ctl: Insufficient granularity of access control in UEFI firmware
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 13 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
Weaknesses CWE-1220
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2025-02-13T15:14:16.353Z

Reserved: 2024-06-25T03:00:08.185Z

Link: CVE-2024-39279

cve-icon Vulnrichment

Updated: 2025-02-13T15:14:11.265Z

cve-icon NVD

Status : Received

Published: 2025-02-12T22:15:35.937

Modified: 2025-02-12T22:15:35.937

Link: CVE-2024-39279

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-12T21:19:32Z

Links: CVE-2024-39279 - Bugzilla

cve-icon OpenCVE Enrichment

No data.