Impact
Improper access control within Intel processors running in Ring 3 enables a local user application to elevate privileges. The flaw allows an attacker who is already authenticated to execute code with higher authority, potentially compromising confidentiality and integrity of the system. No availability impact is seen as the flaw does not disrupt services directly. The weakness is classified as CWE‑284: Improper Access Control.
Affected Systems
The vulnerability affects Intel(R) Processors. No specific models or firmware versions are listed; the advisory does not provide detailed version information or a list of affected configurations.
Risk and Exploitability
The CVSS score of 7.2 indicates a high potential impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation under current threat landscape. Attackers would need local, authenticated access and significant internal knowledge, with no user interaction required. The vulnerability is not listed in the CISA KEV catalog, which implies no widespread exploitation has been documented yet.
OpenCVE Enrichment