Impact
Improper input validation in firmware of certain Intel Xeon processors may allow an attacker with privileged local access to modify system data. The flaw can be exploited after the CPU starts, requiring a high complexity adversary and no user interaction. Once the attack succeeds, it can raise the attacker’s privileges and produce a high integrity impact, while confidentiality and availability remain unaffected.
Affected Systems
The vulnerability impacts some Intel Xeon processors whose firmware contains the flawed input validation. Exact model or firmware versions were not disclosed, so any Xeon processor supplied by Intel whose firmware implements this logic could be affected.
Risk and Exploitability
The CVSS score of 4.0 indicates a moderate severity. With no EPSS data available, the likelihood of exploitation is unclear, and the vulnerability is not listed in CISA’s KEV catalog. It is presumed to be exploitable only in a local environment by an attacker who already has privileged access, making it a conditional risk that requires patching or mitigating controls by the system owner.
OpenCVE Enrichment