Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
Conclusion & alert: CVE-2020-24489 is rated Moderate Risk (42.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.07%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.04% | 0.07% | +0.03% |
| 2 | 2023-03-07 | 0.89% | 0.04% | -0.85% |
| 3 | 2022-04-01 | — | 0.89% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.0 | 6.0 | [email protected] |
| 4.6 | 2.0 | MEDIUM |
|
3.9 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2020-24489: 1 source package rows (intel-ucode); 7 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2020-24489 |
debian
|
not yet assigned | CVE-2020-24489 not yet assigned priority: Debian including 1 source packages (intel-microcode), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-24489 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2020-24489 |
suse
|
high | CVE-2020-24489 severity important: SUSE including 17 source package names (microcode_ctl-1.17-102.83.71.1, microcode_ctl-2.1-73.11.el7_9, …), 72 product×package rows across 72 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-SAP-Azure-LI-BYOS-Production, … (72 product lines)): Fixed 72. | https://www.suse.com/security/cve/CVE-2020-24489/ |
ubuntu
|
high | CVE-2020-24489 high priority: Ubuntu including 1 source packages (intel-microcode), 9 status rows across 9 suites (bionic, focal, groovy, hirsute, impish, jammy, trusty, upstream, xenial): released 8, needs-triage 1. | https://ubuntu.com/security/CVE-2020-24489 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| intel | atom_x5-e3930 | — | cpe:2.3:h:intel:atom_x5-e3930:-:*:*:*:*:*:*:* |
| intel | atom_x5-e3940 | — | cpe:2.3:h:intel:atom_x5-e3940:-:*:*:*:*:*:*:* |
| intel | atom_x7-e3950 | — | cpe:2.3:h:intel:atom_x7-e3950:-:*:*:*:*:*:*:* |
| intel | celeron_j1750 | — | cpe:2.3:h:intel:celeron_j1750:-:*:*:*:*:*:*:* |
| intel | celeron_j1800 | — | cpe:2.3:h:intel:celeron_j1800:-:*:*:*:*:*:*:* |
| intel | celeron_j1850 | — | cpe:2.3:h:intel:celeron_j1850:-:*:*:*:*:*:*:* |
| intel | celeron_j1900 | — | cpe:2.3:h:intel:celeron_j1900:-:*:*:*:*:*:*:* |
| intel | celeron_j3060 | — | cpe:2.3:h:intel:celeron_j3060:-:*:*:*:*:*:*:* |
| intel | celeron_j3160 | — | cpe:2.3:h:intel:celeron_j3160:-:*:*:*:*:*:*:* |
| intel | celeron_j3355 | — | cpe:2.3:h:intel:celeron_j3355:-:*:*:*:*:*:*:* |
| intel | celeron_j3355e | — | cpe:2.3:h:intel:celeron_j3355e:-:*:*:*:*:*:*:* |
| intel | celeron_j3455 | — | cpe:2.3:h:intel:celeron_j3455:-:*:*:*:*:*:*:* |
| intel | celeron_j3455e | — | cpe:2.3:h:intel:celeron_j3455e:-:*:*:*:*:*:*:* |
| intel | celeron_j4005 | — | cpe:2.3:h:intel:celeron_j4005:-:*:*:*:*:*:*:* |
| intel | celeron_j4025 | — | cpe:2.3:h:intel:celeron_j4025:-:*:*:*:*:*:*:* |
| intel | celeron_j4105 | — | cpe:2.3:h:intel:celeron_j4105:-:*:*:*:*:*:*:* |
| intel | celeron_j4115 | — | cpe:2.3:h:intel:celeron_j4115:-:*:*:*:*:*:*:* |
| intel | celeron_j4125 | — | cpe:2.3:h:intel:celeron_j4125:-:*:*:*:*:*:*:* |
| intel | celeron_j6412 | — | cpe:2.3:h:intel:celeron_j6412:-:*:*:*:*:*:*:* |
| intel | celeron_j6413 | — | cpe:2.3:h:intel:celeron_j6413:-:*:*:*:*:*:*:* |
| intel | celeron_n2805 | — | cpe:2.3:h:intel:celeron_n2805:-:*:*:*:*:*:*:* |
| intel | celeron_n2806 | — | cpe:2.3:h:intel:celeron_n2806:-:*:*:*:*:*:*:* |
| intel | celeron_n2807 | — | cpe:2.3:h:intel:celeron_n2807:-:*:*:*:*:*:*:* |
| intel | celeron_n2808 | — | cpe:2.3:h:intel:celeron_n2808:-:*:*:*:*:*:*:* |
| intel | celeron_n2810 | — | cpe:2.3:h:intel:celeron_n2810:-:*:*:*:*:*:*:* |
| intel | celeron_n2815 | — | cpe:2.3:h:intel:celeron_n2815:-:*:*:*:*:*:*:* |
| intel | celeron_n2820 | — | cpe:2.3:h:intel:celeron_n2820:-:*:*:*:*:*:*:* |
| intel | celeron_n2830 | — | cpe:2.3:h:intel:celeron_n2830:-:*:*:*:*:*:*:* |
| intel | celeron_n2840 | — | cpe:2.3:h:intel:celeron_n2840:-:*:*:*:*:*:*:* |
| intel | celeron_n2910 | — | cpe:2.3:h:intel:celeron_n2910:-:*:*:*:*:*:*:* |
| intel | celeron_n2920 | — | cpe:2.3:h:intel:celeron_n2920:-:*:*:*:*:*:*:* |
| intel | celeron_n2930 | — | cpe:2.3:h:intel:celeron_n2930:-:*:*:*:*:*:*:* |
| intel | celeron_n2940 | — | cpe:2.3:h:intel:celeron_n2940:-:*:*:*:*:*:*:* |
| intel | celeron_n3000 | — | cpe:2.3:h:intel:celeron_n3000:-:*:*:*:*:*:*:* |
| intel | celeron_n3010 | — | cpe:2.3:h:intel:celeron_n3010:-:*:*:*:*:*:*:* |
| intel | celeron_n3050 | — | cpe:2.3:h:intel:celeron_n3050:-:*:*:*:*:*:*:* |
| intel | celeron_n3060 | — | cpe:2.3:h:intel:celeron_n3060:-:*:*:*:*:*:*:* |
| intel | celeron_n3150 | — | cpe:2.3:h:intel:celeron_n3150:-:*:*:*:*:*:*:* |
| intel | celeron_n3160 | — | cpe:2.3:h:intel:celeron_n3160:-:*:*:*:*:*:*:* |
| intel | celeron_n3350 | — | cpe:2.3:h:intel:celeron_n3350:-:*:*:*:*:*:*:* |
| intel | celeron_n3350e | — | cpe:2.3:h:intel:celeron_n3350e:-:*:*:*:*:*:*:* |
| intel | celeron_n3450 | — | cpe:2.3:h:intel:celeron_n3450:-:*:*:*:*:*:*:* |
| intel | celeron_n4000 | — | cpe:2.3:h:intel:celeron_n4000:-:*:*:*:*:*:*:* |
| intel | celeron_n4000c | — | cpe:2.3:h:intel:celeron_n4000c:-:*:*:*:*:*:*:* |
| intel | celeron_n4020 | — | cpe:2.3:h:intel:celeron_n4020:-:*:*:*:*:*:*:* |
| intel | celeron_n4020c | — | cpe:2.3:h:intel:celeron_n4020c:-:*:*:*:*:*:*:* |
| intel | celeron_n4100 | — | cpe:2.3:h:intel:celeron_n4100:-:*:*:*:*:*:*:* |
| intel | celeron_n4120 | — | cpe:2.3:h:intel:celeron_n4120:-:*:*:*:*:*:*:* |
| intel | celeron_n4500 | — | cpe:2.3:h:intel:celeron_n4500:-:*:*:*:*:*:*:* |
| intel | celeron_n4505 | — | cpe:2.3:h:intel:celeron_n4505:-:*:*:*:*:*:*:* |
| intel | celeron_n5095 | — | cpe:2.3:h:intel:celeron_n5095:-:*:*:*:*:*:*:* |
| intel | celeron_n5100 | — | cpe:2.3:h:intel:celeron_n5100:-:*:*:*:*:*:*:* |
| intel | celeron_n5105 | — | cpe:2.3:h:intel:celeron_n5105:-:*:*:*:*:*:*:* |
| intel | celeron_n6210 | — | cpe:2.3:h:intel:celeron_n6210:-:*:*:*:*:*:*:* |
| intel | celeron_n6211 | — | cpe:2.3:h:intel:celeron_n6211:-:*:*:*:*:*:*:* |
| intel | core_i3-1000g1 | — | cpe:2.3:h:intel:core_i3-1000g1:-:*:*:*:*:*:*:* |
| intel | core_i3-1000g4 | — | cpe:2.3:h:intel:core_i3-1000g4:-:*:*:*:*:*:*:* |
| intel | core_i3-1000ng4 | — | cpe:2.3:h:intel:core_i3-1000ng4:-:*:*:*:*:*:*:* |
| intel | core_i3-1005g1 | — | cpe:2.3:h:intel:core_i3-1005g1:-:*:*:*:*:*:*:* |
| intel | core_i3-10100 | — | cpe:2.3:h:intel:core_i3-10100:-:*:*:*:*:*:*:* |
| intel | core_i3-10100e | — | cpe:2.3:h:intel:core_i3-10100e:-:*:*:*:*:*:*:* |
| intel | core_i3-10100f | — | cpe:2.3:h:intel:core_i3-10100f:-:*:*:*:*:*:*:* |
| intel | core_i3-10100t | — | cpe:2.3:h:intel:core_i3-10100t:-:*:*:*:*:*:*:* |
| intel | core_i3-10100te | — | cpe:2.3:h:intel:core_i3-10100te:-:*:*:*:*:*:*:* |
| intel | core_i3-10100y | — | cpe:2.3:h:intel:core_i3-10100y:-:*:*:*:*:*:*:* |
| intel | core_i3-10105 | — | cpe:2.3:h:intel:core_i3-10105:-:*:*:*:*:*:*:* |
| intel | core_i3-10105f | — | cpe:2.3:h:intel:core_i3-10105f:-:*:*:*:*:*:*:* |
| intel | core_i3-10105t | — | cpe:2.3:h:intel:core_i3-10105t:-:*:*:*:*:*:*:* |
| intel | core_i3-10110u | — | cpe:2.3:h:intel:core_i3-10110u:-:*:*:*:*:*:*:* |
| intel | core_i3-10110y | — | cpe:2.3:h:intel:core_i3-10110y:-:*:*:*:*:*:*:* |
| intel | core_i3-10300 | — | cpe:2.3:h:intel:core_i3-10300:-:*:*:*:*:*:*:* |
| intel | core_i3-10300t | — | cpe:2.3:h:intel:core_i3-10300t:-:*:*:*:*:*:*:* |
| intel | core_i3-10305 | — | cpe:2.3:h:intel:core_i3-10305:-:*:*:*:*:*:*:* |
| intel | core_i3-10305t | — | cpe:2.3:h:intel:core_i3-10305t:-:*:*:*:*:*:*:* |
| intel | core_i3-10320 | — | cpe:2.3:h:intel:core_i3-10320:-:*:*:*:*:*:*:* |
| intel | core_i3-10325 | — | cpe:2.3:h:intel:core_i3-10325:-:*:*:*:*:*:*:* |
| intel | core_i3-11100b | — | cpe:2.3:h:intel:core_i3-11100b:-:*:*:*:*:*:*:* |
| intel | core_i3-1110g4 | — | cpe:2.3:h:intel:core_i3-1110g4:-:*:*:*:*:*:*:* |
| intel | core_i3-1115g4 | — | cpe:2.3:h:intel:core_i3-1115g4:-:*:*:*:*:*:*:* |
| intel | core_i3-1115g4e | — | cpe:2.3:h:intel:core_i3-1115g4e:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2021/07/msg00022.html | Mailing List Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4934 | Third Party Advisory |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00442.html | Vendor Advisory |