Recommended Free Tools
Intel has issued multiple security advisories for server-board update software and firmware, but they do not describe one flaw affecting every Intel server. For the SysFwUpdt issues, Intel’s stated fix is version 16.0.12 or later; several platform families also have separate BIOS or system-firmware package thresholds. A distinct advisory covers BMC firmware, while Intel says its S2600ST Family BIOS and Firmware Update software has no planned fix and should be discontinued or uninstalled. Check the advisory for your exact system family and component before selecting an update.
Which Intel server components are affected?
The advisories cover separate components, vulnerabilities, and hardware families. SysFwUpdt is Intel’s System Firmware Update Utility; BIOS/SFUP package versions and BMC firmware are separate items to check. A utility update alone does not establish that every component on a system is current.
| Advisory | Component and issue | Intel’s stated action |
|---|---|---|
| INTEL-SA-01412, released and last revised February 10, 2026 | CVE-2025-35999: incorrect permission assignment in SysFwUpdt before 16.0.12 | Update SysFwUpdt to 16.0.12 or later |
| INTEL-SA-01325, released and last revised February 10, 2026 | CVE-2025-25210 and CVE-2025-22453: improper input validation in SysFwUpdt before 16.0.12 | Update SysFwUpdt and check the additional platform package thresholds below |
| INTEL-SA-01410, released and last revised May 12, 2026 | CVE-2025-35969: uncontrolled search path in Server Firmware Update Utility Software before 16.0.12 | Update the utility to 16.0.12 or later |
| INTEL-SA-00990, released and last revised February 11, 2025 | Multiple BMC firmware vulnerabilities, including privilege escalation, information disclosure, and denial of service | Use the advisory’s affected-family table and matching BMC firmware threshold |
| INTEL-SA-01183, released and last revised November 12, 2024 | Two privilege-escalation vulnerabilities in S2600ST Family BIOS and Firmware Update software | Intel says there is no planned fix; uninstall or discontinue use of the update software |
These are Intel’s published advisory findings, not evidence that a particular system is affected or has already been remediated. Match the full board or system family and the installed component versions against the relevant advisory.
What fixes do the SysFwUpdt advisories specify?
SysFwUpdt version threshold
For CVE-2025-35999, Intel describes a local privilege-escalation issue caused by incorrect permissions in SysFwUpdt for Intel Server Boards and Systems before version 16.0.12. The described attack requires a privileged user, has low attack complexity, and involves passive user interaction. Intel assigns it CVSS 4.0 5.4 (Medium) and CVSS 3.1 6.7 (Medium), and recommends SysFwUpdt 16.0.12 or later.
#1 Best Overall
- Intel LGA 1700 socket: Ready for 13th Gen Intel Core processors & 12th Gen Intel Core, Pentium Gold and Celeron Processors
- Enhanced power solution: DrMOS, ProCool connector, alloy chokes and durable capacitors for stable power delivery
- Next-gen connectivity: Dual PCIe 5.0 Safeslots, dual PCIe 3.0 slots, 3 x M.2 PCIe 4.0, SlimSAS, dual Intel 2.5Gb Ethernet, front panel USB 3.2 Gen2x2 Type-C, Thunderbolt 4 header support, TPM header, LPT header.
- Comprehensive cooling: Large VRM heatsink, M.2 heatsinks, hybrid fan headers and Fan Xpert 4
- Advanced security management: USB port management, software blacklisting and Regedit on/off controls via ASUS Control Center Express
The other cited SysFwUpdt advisories use the same utility threshold. INTEL-SA-01325 covers two improper-input-validation flaws, CVE-2025-25210 and CVE-2025-22453; Intel rates each CVSS 4.0 7.1 (High), with differing attack-complexity details. INTEL-SA-01410 covers CVE-2025-35969, an uncontrolled-search-path issue rated CVSS 4.0 5.4 (Medium). A CVSS rating describes severity under that scoring system; it is not a measure of how likely a flaw is to be exploited in the wild.
Additional BIOS/SFUP thresholds
INTEL-SA-01325 gives these platform package thresholds in addition to the utility update:
Rank #2
- LGA 2011-3 Dual CPU Motherboard: Intel series LGA 2011-3 socket and dual CPU design, supports Intel Xeon E5 series processors. (e.g. E5 2678 V3/E5 2629 V3/E5 2649 V3/E5 2676 V3/E5 2673 V3/E5 2666 V3, etc.)
- Maximum memory 256GB: The lga 2011-v3 server motherboard supports 8-channel DDR4 or DDR4 ECC memory up to 256GB, support 2133/2400MHZ. Support desktop memory/server memory. The server ram can't work with the desktop ram. When using E5 V4 CPU, it is not compatible with desktop memory (non-ECC), please use server memory (ECC)
- Ultimate Gaming Connectivity: 2 gigabit network interfaces with onboard ReaItek8111 chip for fast and smooth gaming networking. Featuring dual M. 2 slots (NVMe SSD), 4*PCI-Ex16; 10*SATA 3.0; 6*USB 3.0; 6*USB 2.0
- Professional Heat Dissipation: The X99 gaming motherboard is equipped with 3 VRM heat sinks, to realize rapid heat dissipation and keep your system running reliably
- Stable Power Supply: 24pin+8pin+8pin power interface, using the 12-phase power supply to ensure stable power supply.(To ensure the normal operation of the intel x99 motherboard, please use a power supply greater than 500W.
- M50CYP and D50TNP: BIOS/SFUP R01.01.0010 or later.
- D50DNP and M50FCP: BIOS/SFUP R01.02.0004 or later.
Do not apply one family’s threshold to another model. Consult the advisory and the Intel download page for the exact board or system before choosing a package.
How to determine whether your system needs an update
- Identify the complete product family. Use the system or board’s exact model designation, not just “Intel server board.” The advisories apply to different families.
- Check each relevant installed version. Record SysFwUpdt, BIOS/SFUP, and BMC firmware versions separately; an update to one component does not confirm the others are current.
- Open the matching Intel advisory. Compare the family and component against its affected-version and fixed-version details. For BMC firmware, use INTEL-SA-00990’s family-specific table.
- Obtain the corresponding package from Intel. Follow the download and installation guidance for that precise product family, including any BIOS/SFUP threshold in INTEL-SA-01325.
- Recheck the installed version. Confirm that the intended utility or firmware package is installed at the applicable threshold rather than assuming a successful download completed remediation.
What is different about the BMC and S2600ST advisories?
BMC firmware is a separate update path
INTEL-SA-00990 concerns BMC firmware, not the SysFwUpdt utility advisories. One example is CVE-2023-25191, a network-accessible privilege-escalation issue in AMI BMC firmware affecting M70KLP, M20NTP, and M10JNP families before their respective fixed versions. Intel rates that vulnerability CVSS 3.1 9.1 (Critical) and CVSS 4.0 9.3 (Critical). The advisory also includes local privilege-escalation issues on other server families. Because affected versions vary, use the advisory’s table rather than assuming these example families or thresholds apply to another system.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- LGA 2011-3 Dual CPU Motherboard: Intel series LGA 2011-3 socket and dual CPU design. And it supports Intel Xeon E5-2XXX-V3, E5-2XXX-V4 series processors. (Note: Please use two CPUs of the same model. Intel Core i7 series processors do not support dual CPU)
- Maximum memory 256GB: The X99 server motherboard supports 8-channel DDR4 ECC/RECC/Desktop memory up to 256GB(8X32GB), 2133/2400MHZ effective frequencies. (Note: The Server RAM can't work with the Desktop RAM. When using E5 V4 CPUs, only ECC or RECC memory is supported, not desktop memory)
- PCIe 3.0 Protocol Standard: Equipped with 2 PCIe 3.0 X16 slots, 1 PCIe 3.0 X8 slot, 2 PCIe 2.0 X1 slots. Equipped with dual M.2 (PCIe 3.0 X4 bandwidth) hard disk slots, it can achieve fast reading even if multiple programs are running
- High-performance Motherboard: The X99 DDR4 motherboard is equipped with C612 chipset, 6-layer PCB material design. Assemble the diagnostic card, you can quickly find the fault location. Besides, dual network ports allow your computer to do more things
- Heat Dissipation and Power Supply: The X99 gaming motherboard is equipped with 3 VRM heat sinks, to realize rapid heat dissipation. And equipped with 24pin+8pin+8pin power interface, using the 6-phase power supply to ensure stable power supply. (Please use a power supply greater than 600W)
S2600ST update software has no planned fix
For the S2600ST Family BIOS and Firmware Update software, INTEL-SA-01183 identifies two privilege-escalation vulnerabilities and says the software is unsupported with no planned fix. Intel recommends uninstalling it or discontinuing its use as soon as possible. This applies to that legacy update software; it is not a statement that all S2600ST board firmware is unpatchable. Intel does not provide a replacement version threshold for that updater.
Quick Recap
Best Value
- Ready for advanced AI PCs: Designed for the future of AI computing, with the power and connectivity needed for demanding AI applications
- Intel LGA1851 socket: Ready for Intel Core Ultra 9, 7, and 5 desktop processors
- Robust performance: 8+1+2+2 teamed power stages, ProCool II power connectors, high-quality alloy chokes and durable capacitors
- Future-proofed connectivity: 1 x Thunderbolt 4 ports, dual 2.5 Gb Ethernet, two PCIe 5.0 with full support for next-gen GPU, and one PCIE 5.0, three PCIe 4.0 M.2 slots and a USB 20Gbps front-panel header
- Exclusive AI and overclocking technologies: AI Cooling II, AI Advisor, and NPU boost
Rank #4
- Supports 12th/13th Gen Intel Core, Pentium Gold and Celeron processors for LGA 1700 socket
- Supports DDR4 Memory, Dual Channel DDR4 5333+MHz (OC)
- Enhanced Power Design: 12+1 Duet Rail Power System with P-PAK, 8-pin + 4-pin CPU power connectors, Core Boost, Memory Boost
- Premium Thermal Solution: Extended Heatsink, MOSFET thermal pads rated for 7W/mK, additional choke thermal pads and M.2 Shield Frozr are built for high performance system and non-stop gaming experience
- High Quality PCB: 6-layer PCB made by 2oz thickened copper and server grade level material
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

