A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.

Project Subscriptions

Vendors Products
Insydeh2o Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24531 A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.
Fixes

Solution

Intel Mobil Platforms: PantherLake: Version 05.71.04.0012 LunarLake: Version 05.62.21.0033 ArrowLake H/U: Version 05.55.17.0017 ArrowLake S/HX: Version 05.55.17.0028 MeteorLake: Version 05.55.17.0036 RapterLake: Version 05.47.21.0055 TwinLake: Version 05.44.45.0027 Intel Server/Embedded Platforms: Purley: Version 05.21.51.0064 Whitley: Version 05.42.23.0078 CedarIsland: Version 05.42.11.0031 Eagle Stream: Version 05.47.31.1049 Birch Stream: Version 05.62.16.0082 Mehlow: Version 05.23.04.0054 Tatlow: Version 05.42.52.0029 Jacobsville: (Not Affected) Harrisonville: (Not Affected) Idaville: Version 05.47.21.0067 WhiskeyLake: Version 05.23.45.0032 CometLake-S: Version 05.34.19.0050 TigerLake UP3/H: Version 05.43.12.0062 AlderLake: Version 05.47.21.2055 Gemini Lake: (Not Affected) ElkhartLake: Version 05.47.21.0028 Alder Lake N: Version 05.47.21.0013 AmstonLake: Version 05.47.21.0008


Workaround

No workaround given by the vendor.

History

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Insyde
Insyde insydeh2o
Vendors & Products Insyde
Insyde insydeh2o

Wed, 13 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.
Title SetupUtility: A buffer overflow vulnerability leads to arbitrary code execution.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Insyde

Published:

Updated: 2025-08-14T05:53:21.108Z

Reserved: 2025-05-07T06:45:13.610Z

Link: CVE-2025-4410

cve-icon Vulnrichment

Updated: 2025-08-13T13:17:33.453Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T03:15:32.790

Modified: 2025-08-13T17:33:46.673

Link: CVE-2025-4410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-13T21:47:04Z

Weaknesses