Intel UEFI Firmware Information Disclosure Vulnerability in 4th and 5th Generation Xeon Scalable Processors

Vulnerability

A vulnerability allowing information disclosure has been identified in the UEFI firmware of certain Intel platforms, specifically in Ring 0: Bare Metal OS. This issue arises from improper initialization and may be exploited by a system software adversary with privileged user access. The vulnerability requires a high complexity attack and could lead to data exposure via local access, without the need for special internal knowledge or user interaction. While the vulnerability itself is assessed to have a high impact on confidentiality, it does not affect integrity or availability. However, the potential exploitation could result in no confidentiality, integrity, or availability impacts on the system.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users of 4th and 5th Generation Intel Xeon Scalable processors are advised to update to the latest version provided by their system manufacturer that addresses this issue.

Added: May 12, 2026, 5:28 PM
Updated: May 12, 2026, 5:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
2.4
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.