Intel UEFI Improper Buffer Restrictions in DXE Module Allow Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in the UEFI DXE module for certain Intel Reference Platforms, where improper buffer restrictions may lead to information disclosure. This vulnerability allows a system software adversary with privileged user access to expose data. The attack is complex but can potentially be executed locally, without special internal knowledge or user interaction. While the vulnerability itself may have a low impact on confidentiality, it could lead to greater confidentiality issues within the system.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure.

Remediation

Users are advised to update to the latest UEFI firmware version provided by their system manufacturer that addresses this vulnerability.

Added: Mar 10, 2026, 11:25 PM
Updated: Mar 10, 2026, 11:25 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
2.4
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.