ZeroHour

CVE-2026-20901

CVSS 4.0
4.0 medium
EPSS
<1%p1
Published
()
Modified
Description

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

Vendors
intel
Products
xeon bronze 3408u firmware, xeon gold 5403n firmware, xeon gold 5411n firmware, xeon gold 5412u firmware, xeon gold 5415\+ firmware, xeon platinum 8592\+ firmware, xeon platinum 8592v firmware, xeon platinum 8593q firmware, xeon silver 4509y firmware, xeon silver 4510 firmware, xeon silver 4510t firmware, xeon silver 4514y firmware
Weakness
CWE-20
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.