Intel Memory and Storage Tool < 2.5.2 Escalation of Privilege (INTEL-SA-01414)

medium Nessus Plugin ID 298884

Synopsis

The remote host is missing a security update.

Description

The version of Intel Memory and Storage Tool installed on the remote host is prior to 2.5.2. It is, therefore, affected by a vulnerability as referenced in the INTEL-SA-01414 advisory.

- Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3 User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction (CVE-2025-36511)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade Intel Memory and Storage Tool to version 2.5.2 or later.

See Also

http://www.nessus.org/u?eb14ee84

Plugin Details

Severity: Medium

ID: 298884

File Name: intel_mas_INTEL-SA-01414.nasl

Version: 1.2

Type: local

Agent: windows

Family: Windows

Published: 2/12/2026

Updated: 2/13/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Medium

Base Score: 6

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-36511

CVSS v3

Risk Factor: Medium

Base Score: 6.7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: x-cpe:/a:intel:memory_and_storage_tool

Required KB Items: installed_sw/Intel Memory and Storage Tool

Patch Publication Date: 2/10/2026

Vulnerability Publication Date: 2/10/2026

Reference Information

CVE: CVE-2025-36511

IAVB: 2026-B-0044