Executive brief
Intel processors contain a vulnerability in their core execution environment (Ring 0) that allows an authorized user with elevated privileges to escalate their access further. An attacker would need existing high-level access and specialized knowledge to exploit this, but successful exploitation could compromise the confidentiality and integrity of the entire system, including any operating system, hypervisor, or virtual machines running on the affected processor.
Technical details
The vulnerability involves improper handling of values within Intel processor Ring 0 (the most privileged CPU execution mode), affecting the kernel, hypervisor, and bare metal operating systems. The vulnerability requires local access, an authorized adversary with existing privileged (high) user status, and high complexity attack requirements combined with special internal knowledge. No user interaction is needed. An attacker can achieve escalation of privilege with low initial impact on confidentiality and integrity but high subsequent impact on system-wide confidentiality and integrity. Intel has released microcode updates available through their public GitHub repository and recommends firmware updates from system manufacturers.
Affected products
- Intel Core Ultra Processors Series 1 Meteor Lake (A06A1, A06A2, A06A3, A06A4)
- Intel Core Ultra Processors Series 2 Arrow Lake (B0650, C0662, C0652, C0664), Lunar Lake (B06D1)
- Intel Core Ultra Processors Series 3 Panther Lake (C06C2, C06C3)
- Intel Xeon 6 Processors with P-Cores Birch Stream (A06D1, A06E1)
- Intel Xeon 6700P-B/6500P-B Series Kaseyville (A06E1)
Timeline
- 2026-08-11: advisory: Intel-SA-01428 advisory published with microcode updates