Junglewise Threat Intelligence

CVE-2026-20713: Intel Xeon firmware control flow privilege escalation

CVE-2026-20713 · Severity: info · CVSS 4.5 · Published 2026-08-11

Technologies: Intel Xeon 6 processor with P-cores, Intel Xeon 6 SoC. Vendors: Intel.

Executive brief

Intel Xeon processors contain a firmware vulnerability that could allow a privileged attacker on the local system to escalate their privileges further. An exploit requires system-level access, high technical complexity, and knowledge of internal processor details. If successful, an attacker could gain unauthorized read and write access to protected system memory and data.

Technical details

An always-incorrect control flow implementation in Intel Xeon processor firmware allows privilege escalation when exploited by a system software adversary. The vulnerability requires the attacker to already possess privileged user access and involves a high-complexity local attack with no additional special requirements beyond system knowledge. The root cause stems from improper control flow logic in the processor's firmware that fails to enforce proper access boundaries. Exploitation can result in high impact to system confidentiality and integrity by allowing an attacker to read and modify protected memory regions. Intel is addressing this through microcode updates distributed via system manufacturers.

Affected products

  • Intel Xeon Scalable Processor (4th Gen) All versions prior to microcode mitigation
  • Intel Xeon W2400 and W3400 Processors All versions prior to microcode mitigation
  • Intel Xeon Scalable Processor (5th Gen) All versions prior to microcode mitigation
  • Intel Xeon 6 Processor with P-cores All versions prior to microcode mitigation
  • Intel Xeon 6 SoC All versions prior to microcode mitigation
  • Intel Xeon 6 Processor with E-cores All versions prior to microcode mitigation

Timeline

  • 2026-08-11: disclosed: Intel PSIRT advisory INTEL-SA-01442 published

References

Related threats