Impact
An improper initialization flaw in the UEFI firmware of certain Intel platforms allows a privileged Bare Metal OS to acquire sensitive data due to a missing or corrupted state setup. The vulnerability is a classic initialization error classified as CWE-665. The primary consequence is a high confidentiality impact with no integrity or availability effects.
Affected Systems
The flaw affects Intel platform firmware exposed through UEFI. Specific model or firmware version details are not provided; it applies to any affected Intel platform that has not been updated to a firmware version that corrects the improper initialization issue.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability can be exploited locally by an adversary who already has a privileged user in the bare metal OS and can perform a complex attack without special internal knowledge or user interaction. Because the attack requires local access and elevated OS privileges, the likelihood is moderate for environments where such access can be achieved, but the risk is lower for systems with strict privilege separation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment