Description
Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.
Published: 2026-08-11
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an integer overflow in the UEFI firmware of Intel’s Slim Bootloader (CWE‑190). An attacker who can execute a local instruction with an authenticated user can trigger the overflow through a low‑complexity action that requires the user to interact with the system. The overflow may expose data stored in the firmware and can also lead to a denial‑of‑service condition. The documented impact is a low confidentiality effect, no integrity impact, and a low availability impact.

Affected Systems

All systems that run the Intel Slim Bootloader firmware are potentially affected. The advisory does not list specific firmware versions, so any device using the Slim Bootloader should be checked for the integer‑overflow flaw, and vendors should refer to the attached Intel Security Advisory for guidance.

Risk and Exploitability

The CVSS score of 2.4 reflects the limited impact. With an EPSS score below 1%, the likelihood of real‑world exploitation is very low at the time of this analysis, and the flaw is not listed in CISA’s KEV catalog. The attack can be carried out only with local authenticated access and requires user interaction, so the overall risk remains low but the vulnerability still warrants remediation.

Generated by OpenCVE AI on August 12, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the UEFI firmware to a version that fixes the integer overflow in the Intel Slim Bootloader.
  • Restrict local user privileges to limit access to firmware configuration interfaces, thereby reducing the chances that an authenticated user can trigger the overflow.
  • Monitor system logs and firmware behavior for anomalous activity that could indicate attempts to exploit the overflow.

Generated by OpenCVE AI on August 12, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel slim Bootloader
Vendors & Products Intel
Intel slim Bootloader

Wed, 12 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Intel Slim Bootloader UEFI Firmware Leading to Information Disclosure and Denial of Service

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:L/SC:L/SI:N/SA:L'}


Subscriptions

Intel Slim Bootloader
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:20:48.694Z

Reserved: 2026-03-13T03:00:21.486Z

Link: CVE-2026-28729

cve-icon Vulnrichment

Updated: 2026-08-12T15:20:41.976Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:57.097

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-28729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound