Database/Firmware, BMC & network fabric
Intel CSME firmware (TOCTOU): A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalate
Impact
A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalate into the management engine. Recent, and a reminder that the CSME attack surface is still producing findings on current platforms.
Who can reach it
Privileged local access on the host, plus winning a race.
What to do
Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines.
References
Related entries
- Intel Xeon processor firmware (SGX enabled): Improper buffer restrictions in Xeon firmware on SGX-enabled parts, givingCVE-2025-20053 · Intel Xeon processor firmware (SGX enabled)High
- Intel Xeon 6 memory subsystem (with SGX or TDX): An out-of-bounds write in the Xeon 6 memory subsystem reachable whenCVE-2025-26403 · Intel Xeon 6 memory subsystem (with SGX or TDX)High
- Intel Xeon 6 DDRIO configuration (with SGX or TDX): An improperly implemented security check in DDRIO configuration onCVE-2025-32086 · Intel Xeon 6 DDRIO configuration (with SGX or TDX)High
- AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userCVE-2025-58770 · AMI AptioV UEFI BIOSHigh
- Supermicro BMC firmware validation (MBD-X13SEM-F): Second-generation RoT bypassCVE-2025-6198 · Supermicro BMC firmware validation (MBD-X13SEM-F)High
- AMD Pensando ionic driver on ESXi: untrusted pointer dereference lets a guest VM read kernel and co-tenant memoryCVE-2025-62627 · AMD Pensando ionic cloud driver for VMware ESXi (DPU datapath)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.