ZeroHour

CVE-2026-20716

CVSS 4.0
7.2 high
EPSS
<1%p0
Published
()
Modified
Description

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Vendors
intel
Products
xeon 634 firmware, xeon 636 firmware, xeon 638 firmware, xeon 654 firmware, xeon 656 firmware, xeon 658x firmware, xeon 674x firmware, xeon 676x firmware, xeon 678x firmware, xeon 696x firmware, xeon 698x firmware, xeon 6315p firmware
Weakness
CWE-284
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.