Cyber Posture

CVE-2023-43758

High

Published: 12 February 2025

Published
12 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0002 6.1th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

Security Summary

CVE-2023-43758 is an improper input validation vulnerability, classified under CWE-20, affecting UEFI firmware on some Intel processors. Published on 2025-02-12, it carries a CVSS v3.1 base score of 8.2 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), indicating high severity due to its potential for significant impact across confidentiality, integrity, and availability.

The vulnerability can be exploited by a privileged user with local access, who may leverage improper input validation to escalate privileges. Successful exploitation requires high privileges and low complexity but no user interaction, with a changed scope that amplifies effects on the system.

Intel's security advisory (INTEL-SA-01139) addresses the issue, and a Debian LTS announcement details mitigations for affected packages.

Details

CWE(s)
CWE-20

References