Intel CIP Software Improper Access Control Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability exists in some Intel CIP software prior to version WIN_DCA_2.4.0.11001, specifically within Ring 3: User Applications. This vulnerability involves improper access control that may lead to unauthorized information disclosure. An unprivileged software adversary with a privileged user can exploit this issue, potentially allowing data exposure. The vulnerability may be triggered through adjacent access, without special internal knowledge, and requires no user interaction. The impact of this vulnerability is high on confidentiality, with no effects on integrity or availability.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure, allowing sensitive data to be exposed.

Remediation

Users are advised to update Intel CIP software to version WIN_DCA_2.4.0.11001 or later. The update is available for download from the Intel Download Center.

Added: Nov 11, 2025, 6:38 PM
Updated: Nov 11, 2025, 6:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.