Database/Firmware, BMC & network fabric

Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on Intel
Impact
Improper input validation in a UEFI DXE driver on Intel Server D50DNP boards gives a privileged local user escalation into firmware. D50DNP is a dense datacenter server board, so this is squarely an AI-datacenter platform. Firmware-level escalation means persistence below the OS that survives reimaging.
Who can reach it
Privileged local access on the host.
What to do
Fixed in platform BIOS/UEFI firmware. That means an OEM release, a per-node drain, a flash and a cold reboot - and OEM availability commonly lags the Intel advisory by quarters on server boards. There is no microcode or OS-level shortcut for this class; budget it as a fleet-wide maintenance campaign, not a patch.
References
Related entries
- Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it shouldCVE-2024-22453 · Dell PowerEdge Server BIOS (heap-based buffer overflow)High
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCCVE-2024-38509 · Lenovo XClarity Controller (XCC) - IPMI command handlerHigh
- AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedCVE-2024-42442 · AMI AptioV UEFI BIOS (SMM)High
- AMD Zen microcode patch loader (CPU ROM signature verification): The CPU ROM's microcode patch loader verified patchCVE-2024-56161 · AMD Zen microcode patch loader (CPU ROM signature verification)High
- AMD CPU microcode patch loading - improper cleanup: Improper cleanup during microcode patch loading gives a localCVE-2025-0032 · AMD CPU microcode patch loading - improper cleanupHigh
- Supermicro BMC firmware validation logic on the X12STW-F motherboard: An attacker with administrative reach to the BMCCVE-2025-12006 · Supermicro BMC firmware validation logic on the X12STW-F motherboardHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.