Executive brief
Intel processors contain an improper access control vulnerability in Ring 3 (user application level) that allows a local attacker with authentication to escalate their privileges on the system. A successful exploitation would give an attacker elevated system access, potentially compromising the confidentiality and integrity of sensitive data and operations running on the affected processor.
Technical details
This vulnerability involves improper access control in some Intel processors that allows user-level applications running in Ring 3 to escalate privileges. The attack requires local access, authentication, high complexity attack, and special internal knowledge; no user interaction is needed. An authenticated local adversary can exploit this to gain elevated privileges, potentially compromising system confidentiality and integrity. Intel is addressing this through microcode updates distributed via system manufacturers.
Affected products
- Intel Xeon 6 processor with P-cores Some versions (see microcode updates)
- Intel Xeon 6 SoC Some versions (see microcode updates)
- Intel Xeon 6 processor Some versions (see microcode updates)
Timeline
- 2026-08-11: disclosed