CVE-2020-24509
Description
Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Insufficient control flow management in Intel SPS firmware allows a privileged local user to escalate privileges on affected platforms.
Vulnerability
A vulnerability in the control flow management of Intel(R) Server Platform Services (SPS) firmware, identified as CVE-2020-24509, allows insufficient validation of certain code paths. Affected versions include those before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, and SPS_E5_04.04.03.263.0. The issue resides in the SPS subsystem and is reachable by a local user with elevated privileges.
Exploitation
An attacker must have local access to the system and possess privileged user credentials (e.g., administrator or root-level access). Once authenticated, the attacker can exploit the insufficient control flow management to bypass intended security checks, potentially executing arbitrary code within the SPS firmware context.
Impact
Successful exploitation allows the attacker to escalate their privileges within the SPS environment, potentially gaining control over platform-level functions such as power management, boot integrity, or system configuration. This could lead to a full compromise of the platform's security boundaries.
Mitigation
Intel has released firmware updates to address this vulnerability: SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, and SPS_E5_04.04.03.263.0. System administrators should update the Intel SPS firmware to the latest fixed versions. No workarounds have been provided, and the vulnerability is not currently listed in the KEV catalog [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Intel/SPSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.netapp.com/advisory/ntap-20210611-0003/mitrex_refsource_CONFIRM
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00459.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.