PT-2026-40078 · Intel · Endpoint Management Assistant
CVE-2025-35990
·
Published
2026-05-12
·
Updated
2026-07-21
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel Endpoint Management Assistant (EMA) versions prior to 1.14.5
Description
Improper input validation within Ring 3: User Applications allows an unprivileged, unauthenticated software adversary to perform an escalation of privilege. This issue can be exploited via adjacent access with low complexity, requiring no user interaction or special internal knowledge. A successful attack may result in high impact on the confidentiality, integrity, and availability of the vulnerable system.
Recommendations
Update Intel Endpoint Management Assistant (EMA) to version 1.14.5 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Endpoint Management Assistant