Impact
The flaw is an integer overflow in the UEFI firmware of Intel’s Slim Bootloader (CWE‑190). An attacker who can execute a local instruction with an authenticated user can trigger the overflow through a low‑complexity action that requires the user to interact with the system. The overflow may expose data stored in the firmware and can also lead to a denial‑of‑service condition. The documented impact is a low confidentiality effect, no integrity impact, and a low availability impact.
Affected Systems
All systems that run the Intel Slim Bootloader firmware are potentially affected. The advisory does not list specific firmware versions, so any device using the Slim Bootloader should be checked for the integer‑overflow flaw, and vendors should refer to the attached Intel Security Advisory for guidance.
Risk and Exploitability
The CVSS score of 2.4 reflects the limited impact. With an EPSS score below 1%, the likelihood of real‑world exploitation is very low at the time of this analysis, and the flaw is not listed in CISA’s KEV catalog. The attack can be carried out only with local authenticated access and requires user interaction, so the overall risk remains low but the vulnerability still warrants remediation.
OpenCVE Enrichment