Description
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-05-12
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper initialization flaw in the UEFI firmware of certain Intel platforms allows a privileged Bare Metal OS to acquire sensitive data due to a missing or corrupted state setup. The vulnerability is a classic initialization error classified as CWE-665. The primary consequence is a high confidentiality impact with no integrity or availability effects.

Affected Systems

The flaw affects Intel platform firmware exposed through UEFI. Specific model or firmware version details are not provided; it applies to any affected Intel platform that has not been updated to a firmware version that corrects the improper initialization issue.

Risk and Exploitability

The CVSS score of 5.6 indicates moderate severity, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability can be exploited locally by an adversary who already has a privileged user in the bare metal OS and can perform a complex attack without special internal knowledge or user interaction. Because the attack requires local access and elevated OS privileges, the likelihood is moderate for environments where such access can be achieved, but the risk is lower for systems with strict privilege separation. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on May 12, 2026 at 17:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Intel’s security advisory for the latest BIOS/UEFI firmware update that fixes the improper initialization issue and apply the update immediately
  • If a firmware update is not yet available, disable or limit access to UEFI services that are not required for normal operation to reduce the attack surface
  • Restrict privileged OS user accounts to only the necessary permissions and monitor for unauthorized data access logs

Generated by OpenCVE AI on May 12, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Improper Initialization in UEFI Firmware Enables Information Disclosure on Intel Platforms

Tue, 12 May 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-665
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-05-12T17:06:21.928Z

Reserved: 2025-04-15T21:18:44.499Z

Link: CVE-2025-35991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-12T17:16:13.587

Modified: 2026-05-12T17:16:13.587

Link: CVE-2025-35991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T18:00:12Z

Weaknesses