Impact
Improper handling of overlap between protected memory ranges in certain Intel microcode can cause a privilege escalation when a hypervisor executes code at ring 0. The flaw, identified as CWE‑1260, would allow a privileged attacker to gain higher privileges, potentially compromising confidentiality, integrity, and availability of the host system. The advisory does not indicate any additional data‑exfiltration or denial‑of‑service capabilities beyond the privilege jump.
Affected Systems
The vulnerability affects Intel processors that contain the specified microcode updates, although no exact model or firmware revision is listed. Systems running those processors are at risk when a trusted hypervisor is present. Administrators should verify which processor families are running the affected microcode and determine if a patch exists.
Risk and Exploitability
The CVSS score of 6.8 reflects a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The flaw requires a privileged user with a hypervisor, is low complexity, and does not need user interaction, so it is a local threat. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known, but the potential impact remains high if an attacker can gain control.
OpenCVE Enrichment