Junglewise Threat Intelligence

CVE-2025-35991: Intel Xeon Scalable Processors improper initialization in UEFI firmware

CVE-2025-35991 · Severity: info · CVSS 5.6 · Published 2026-05-12

Vendors: Intel.

Executive brief

A vulnerability in the UEFI firmware of certain Intel Xeon Scalable processors could allow a highly privileged local user to access sensitive information. This issue stems from improper initialization during the system's startup phase. While the attack is complex to execute, it could lead to the exposure of data that should remain confidential within the system's most secure operating layer. Intel has released firmware updates to address this issue.

Technical details

An improper initialization vulnerability (CWE-665) exists in the UEFI firmware for 4th and 5th Generation Intel Xeon Scalable processors. The flaw occurs within Ring 0 (Bare Metal OS) and can be exploited by a local adversary with high privileges (system software level). Exploitation requires a high-complexity attack and specific preconditions to be met, but does not require user interaction. If successful, the attacker can achieve high confidentiality impact by accessing protected system data. Intel recommends updating to the latest firmware version provided by system manufacturers.

Affected products

  • Intel 4th Generation Xeon Scalable processor
  • Intel 5th Generation Xeon Scalable processor

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched

References