Impact
Improper input validation in the timer command handler before version 11.3.1 allows an unprivileged task running on MPU‑enabled ports to execute code in privileged kernel context, constituting a privilege escalation flaw (CWE‑863). This can compromise confidentiality, integrity, and availability if an attacker can influence the timer command interface from user space.
Affected Systems
FreeRTOS‑Kernel versions earlier than 11.3.1 on MPU‑enabled ports. Systems that compile the kernel with MPU support and run those older releases are at risk; the fix is included in version 11.3.1 and later.
Risk and Exploitability
The CVSS score of 9.3 classifies the issue as critical. EPSS is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local; it requires an attacker to create or control an unprivileged task that issues malicious timer commands on a device with MPU enabled. Successful exploitation would elevate the task to privileged kernel context.
OpenCVE Enrichment