Draft in the CWE catalog · 10 CVEs mapped
The lack of protections on alternate paths to access
control-protected assets (such as unprotected shadow registers
and other external facing unguarded interfaces) allows an
attacker to bypass existing protections to the asset that are
only performed against the primary path.
🚨 A sneaky gap in Intel's Quick Assist Technology could let a privileged user escalate their access right into the kernel! Think of it like a restaurant where a waiter knows a secret door to the kitchen, allowing them to bypass normal checks and access the chef’s special ingredients. This vulnerability is a similar backdoor for a system adversary to elevate their privileges without raising any alarms. If an attacker gets a foothold, they could potentially manipulate the system’s security, reaching sensitive confidential data and altering key information. While the good news is that it requires local access and insider knowledge, the possible fallout could still be devastating — your system's integrity is at stake!
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unauthorized firmware onto the device.