Impact
The vulnerability arises from improper handling of certain values within Intel processors at Ring 0. An authorized local user with elevated privileges and a high‑complexity attack can potentially elevate their privileges to kernel, hypervisor, or bare‑metal operating‑system level. The CVE description states that this flaw may compromise the confidentiality and integrity of the system at a low level, but once privilege is elevated the adversary could achieve high‑level impact on confidentiality and integrity, while availability remains unaffected.
Affected Systems
The flaw affects all Intel processors that execute code at Ring 0. No specific model or firmware version is listed, so any Intel CPU running a kernel, hypervisor, or bare‑metal OS may be impacted.
Risk and Exploitability
The CVSS score of 4.5 indicates moderate severity, and the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation requires local privileged access, special internal knowledge, high attack complexity, and no user interaction. The primary risk is to systems where privileged users are present or where local privileged accounts can run kernel‑level code.
OpenCVE Enrichment