Information Disclosure Vulnerability in Intel Active Management Technology and Standard Manageability
CVE-2026-20734

5.6MEDIUM

What is CVE-2026-20734?

Improper initialization in specific firmware versions for Intel Active Management Technology (AMT) and Intel Standard Manageability can lead to unintentional exposure of sensitive information. This vulnerability allows a system software adversary with privileged access to potentially disclose data through a low-complexity attack. Local access is sufficient to exploit this issue, requiring no special internal knowledge or user interaction. Affected systems may face risks associated with confidentiality while maintaining the integrity and availability aspects intact.

Affected Version(s)

Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. See references

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.