VYPR

One Boot Flash Update

by Intel

CVEs (2)

  • CVE-2025-27711MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…

  • CVE-2025-25059MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity…