Impact
A flaw in the firmware of certain Intel Xeon processors arises from an always‑incorrect control flow that allows a local attacker with privileged access to bypass normal authorization checks and gain elevated privileges. This escalation can compromise the confidentiality and integrity of the system, potentially leading to broad system compromise once the attacker obtains higher privileges. The weakness is classified as CWE‑670, indicating improper restriction of operations within the code path.
Affected Systems
Intel Xeon processors that run the vulnerable firmware are affected. No specific firmware versions were disclosed, so any Xeon processor not currently running the patched firmware release is potentially vulnerable. The scope includes all servers and workstations equipped with affected Xeon processors.
Risk and Exploitability
The CVSS score of 4.5 reflects a moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation at this time. The exploit requires local access, a privileged user account, and a high‑complexity attack chain, with no user interaction. Because the vulnerability is not listed in the CISA KEV catalog and no public exploit is documented, the immediate risk is low, yet remediation is advisable.
OpenCVE Enrichment