Improper Access Control in Intel(R) Xeon(R) Processor Firmware
CVE-2026-20898

8.5HIGH

What is CVE-2026-20898?

A security flaw in the firmware for certain Intel Xeon processors allows for improper access control, which may enable an escalation of privilege. Exploiting this vulnerability requires a high complexity attack, with adversaries gaining potential access under specific conditions, typically through local means. The vulnerability does not necessitate user interaction, heightening its risk profile. The implications can compromise system confidentiality and integrity, presenting significant security concerns for affected systems.

Affected Version(s)

in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. See references

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.