Impact
Improper access control in the firmware of the Alias Checking Trusted Module on certain Intel Xeon processors allows an attacker with a privileged user and local access to potentially elevate privileges. The flaw requires execution of malicious startup code within System Management Mode (SMM) and is considered a high‑complexity attack. Because it grants higher privilege levels, it can compromise confidentiality and integrity of the system, although availability is not affected.
Affected Systems
The vulnerability affects Intel Xeon processors equipped with the Alias Checking Trusted Module firmware. Devices that have not applied the firmware patch referenced in Intel SA‑01439 are potentially impacted; specific product versions are not listed in the advisory, so all Xeon models that include the module component are at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity impact with high confidentiality and integrity risk. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. Nonetheless, because the attack requires local privileged user access and no user interaction, it remains a threat in environments where privileged users have unprotected access to SMM or firmware. Exploitation would involve crafting startup code that runs in SMM to bypass normal access controls.
OpenCVE Enrichment