Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf43-7r7r-9f4f

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1.8
CVSS3: 3.9

Описание

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

EPSS

Процентиль: 3%
0.00133
Низкий

1.8 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-229

Связанные уязвимости

CVSS3: 3.9
ubuntu
4 месяца назад

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

CVSS3: 2.5
redhat
4 месяца назад

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

CVSS3: 3.9
nvd
4 месяца назад

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

CVSS3: 3.9
debian
4 месяца назад

Improper handling of values in the microcode flow for some Intel(R) Pr ...

CVSS3: 3.9
fstec
4 месяца назад

Уязвимость микропрограммного обеспечения процессоров Intel, связанная с неправильной обработкой значений, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 3%
0.00133
Низкий

1.8 Low

CVSS4

3.9 Low

CVSS3

Дефекты

CWE-229