Junglewise Threat Intelligence

CVE-2026-20712: Intel UEFI Reference BIOS information disclosure via incomplete cleanup

CVE-2026-20712 · Severity: info · CVSS 4 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel UEFI Reference BIOS firmware for various Xeon and Core X processor platforms contains improper memory cleanup that may leak sensitive data. An attacker with elevated system privileges can exploit this via local access to expose confidential information, potentially compromising system security without requiring user interaction or specialized knowledge.

Technical details

The vulnerability exists in UEFI firmware for Intel reference platforms due to incomplete cleanup of sensitive data structures in memory. The flaw allows information disclosure of confidential data when UEFI is accessed. Attack requires local access and high-level privileges (system software adversary) combined with low attack complexity, but no special knowledge or user interaction is required. An attacker can exploit this to read sensitive information from firmware memory, potentially exposing system secrets or configuration data. Patches are available from system manufacturers.

Affected products

  • Intel Xeon D Processor Family UEFI Firmware affected versions unspecified
  • Intel Xeon Scalable Processor Family UEFI Firmware affected versions unspecified
  • Intel 3rd Generation Xeon Scalable Processor Family UEFI Firmware affected versions unspecified
  • Intel 4th Generation Xeon Scalable Processor Family UEFI Firmware affected versions unspecified
  • Intel 5th Generation Xeon Scalable Processor Family UEFI Firmware affected versions unspecified
  • Intel Xeon W Processor Family UEFI Firmware affected versions unspecified
  • Intel Core X-series Processor UEFI Firmware affected versions unspecified
  • Intel Atom C5000 and P5000 Product Family UEFI Firmware affected versions unspecified
  • Intel Atom Processor P6000 UEFI Firmware affected versions unspecified

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: INTEL-SA-01437 published

References