CVE-2023-29157: Intel One Boot Flash Update

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected products

  • Intel One Boot Flash Update: before 14.1.31 (fixed in 14.1.31)

Published 2023-11-14. Last modified 2026-06-17.