Impact
Incomplete cleanup in certain UEFI firmware on Intel reference platforms allows system software adversaries with privileged user accounts to read residual data stored temporarily during firmware operations. This information disclosure can be achieved with low complexity local attacks that do not require user interaction, provided the attacker meets the access prerequisites. Although the CVSS analysis indicates no direct impact on confidentiality, integrity, or availability, the resulting system confidentiality impact is high, exposing potentially sensitive information.
Affected Systems
This vulnerability affects UEFI firmware on Intel reference platforms. Specific firmware versions are not disclosed in the advisory, so all UEFI builds shipped with these reference platforms should be considered potentially vulnerable until a patch is released.
Risk and Exploitability
With a CVSS base score of 4 and an EPSS below 1%, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring privileged access and no special knowledge; therefore organizations with privileged users on these platforms should remain vigilant. Even though the probability is low, the severity of a potential data leakage warrants monitoring of firmware updates and access controls.
OpenCVE Enrichment