Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-22839

CVE-2025-22839: Intel Xeon 6 Privilege Escalation Flaw

CVE-2025-22839 is a privilege escalation vulnerability affecting Intel Xeon 6 Scalable processors through insufficient access control in OOB-MSM. This article covers the technical details, affected systems, and mitigation strategies.

Published:

CVE-2025-22839 Overview

CVE-2025-22839 is a hardware-level access control weakness affecting the Out-of-Band Manageability Services Module (OOB-MSM) in select Intel Xeon 6 Scalable processors. The flaw stems from insufficient granularity of access control [CWE-1220] within the manageability subsystem. A privileged user with adjacent network access can leverage this weakness to escalate privileges on affected platforms.

The vulnerability was disclosed in Intel Security Advisory SA-01310 and carries a CVSS 4.0 base score of 7.3. Exploitation requires high attack complexity and adjacent access, which limits opportunistic abuse. However, successful exploitation compromises the confidentiality and integrity of the affected processor's manageability domain.

Critical Impact

A privileged, adjacent-network attacker can escalate privileges through the OOB-MSM interface on affected Intel Xeon 6 Scalable processors, compromising firmware-level trust boundaries.

Affected Products

  • Intel Xeon 6 Scalable processors (select SKUs, per Intel SA-01310)
  • Platforms exposing the OOB-MSM manageability interface
  • Debian LTS packages referenced in the October 2025 Debian advisory

Discovery Timeline

  • 2025-08-12 - CVE-2025-22839 published to the National Vulnerability Database (NVD)
  • 2025-08-12 - Intel publishes Security Advisory SA-01310
  • 2025-10 - Debian LTS releases coordinated microcode/firmware update
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-22839

Vulnerability Analysis

The Out-of-Band Manageability Services Module (OOB-MSM) provides platform manageability functions independent of the running operating system. On affected Intel Xeon 6 Scalable processors, the OOB-MSM enforces access controls at a coarser granularity than required by the platform's trust model. This gap allows a privileged actor with adjacent-network reach to invoke management functionality that should be gated by stricter authorization.

Because the OOB-MSM operates below the operating system, successful exploitation grants control at a layer traditional endpoint controls cannot observe directly. The result is escalation to a higher-privileged execution context on the platform, with potential impact on firmware integrity and confidentiality of manageability data.

Root Cause

The root cause maps to CWE-1220: Insufficient Granularity of Access Control. The OOB-MSM groups privileged operations under an access boundary that does not distinguish between operations requiring different levels of trust. A user already holding some privileges can therefore reach functions intended for a stricter privilege tier.

Attack Vector

Exploitation requires adjacent-network access to the manageability interface and pre-existing high privileges on the platform. The attack complexity is high and dependent on specific platform conditions. Public proof-of-concept code is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

No verified exploitation code has been published. Refer to the Intel Security Advisory SA-01310 for platform-specific technical guidance.

Detection Methods for CVE-2025-22839

Indicators of Compromise

  • Unexpected changes to Baseboard Management Controller (BMC) or platform firmware configuration recorded in out-of-band logs.
  • Manageability sessions originating from adjacent network segments that were not previously observed accessing OOB-MSM interfaces.
  • Firmware or microcode version mismatches across otherwise identical Xeon 6 hosts.

Detection Strategies

  • Inventory Intel Xeon 6 Scalable processor SKUs against the list in Intel SA-01310 to identify exposed platforms.
  • Correlate BMC and Redfish audit logs with identity telemetry to detect privileged access from unexpected sources.
  • Validate deployed BIOS, microcode, and platform firmware versions against vendor-published fixed builds.

Monitoring Recommendations

  • Restrict and monitor Layer 2 access to management VLANs carrying OOB-MSM traffic.
  • Alert on new administrative logins to BMC or manageability endpoints outside of change windows.
  • Track firmware update events and cross-check hashes with vendor-published values.

How to Mitigate CVE-2025-22839

Immediate Actions Required

  • Apply the microcode and firmware updates referenced in Intel Security Advisory SA-01310 to all affected Xeon 6 Scalable systems.
  • Update Debian systems using the packages listed in the Debian LTS Announcement.
  • Audit and reduce the number of accounts holding privileged access to platform manageability interfaces.

Patch Information

Intel has released microcode and platform firmware updates that address the access control gap in the OOB-MSM. System operators should coordinate updates with hardware vendors, as fixed firmware is typically delivered through OEM BIOS packages. Debian LTS has shipped corresponding package updates for supported distributions.

Workarounds

  • Isolate manageability interfaces on a dedicated, tightly controlled management network to eliminate adjacent-network exposure.
  • Enforce strong authentication and role separation on BMC and Redfish endpoints until firmware updates are deployed.
  • Disable unused OOB-MSM features where supported by the platform vendor.

Refer to the Intel Security Advisory SA-01310 for platform-specific configuration guidance.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.