← Vulnerability feed

Vulnerability record · CVE-2025-35990 · published 12 May 2026

CVE-2025-35990: Intel endpoint management assistant improper input validation vulnerability

Intel · Endpoint Management Assistant

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

8.7 CVSS 4.0 High EPSS 0.22% · top 88.5% CWE-20 · Improper input validation
8.7CVSS 4.0 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
21 Jul 2026Last modified by NVD

Description

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-35990 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12315Intel endpoint management assistant path traversal vulnerabilityPath traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network a…EPSS 1.7%8.8CVE-2022-26341Intel active management technology software development kit insufficiently protected credentials vulnerabilityInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC befor…EPSS 0.47%7.8CVE-2022-30297Intel endpoint management assistant cross-site scripting vulnerabilityCross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via …EPSS 0.17%7.5CVE-2021-0013Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network…EPSS 0.98%7.0CVE-2024-32483Intel endpoint management assistant improper access control vulnerabilityImproper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of pr…EPSS 0.17%5.5CVE-2022-45128Intel endpoint management assistant improper authorization vulnerabilityImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi…EPSS 0.16%5.5CVE-2020-12316Intel endpoint management assistant insufficiently protected credentials vulnerabilityInsufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosu…EPSS 0.28%5.3CVE-2022-38056Intel endpoint management assistant vulnerabilityImproper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2025-35990), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.