Out-of-Bounds Write Vulnerability in Intel Slim Bootloader
CVE-2026-25194

1.8LOW

What is CVE-2026-25194?

An out-of-bounds write vulnerability has been identified in the firmware of the Intel Slim Bootloader. This flaw may allow a local adversary with privileged access to launch a denial of service attack. The exploitation of this vulnerability does not require special internal knowledge and can be executed with a low-complexity attack, posing a risk when the necessary attack conditions are met. Consequently, affected systems may face availability issues, impacting service continuity.

Affected Version(s)

Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. See references

References

CVSS V4

Score:
1.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.