Executive brief
A vulnerability in the Intel Slim Bootloader, which is responsible for initializing hardware and launching the operating system, could allow an attacker to gain higher-level system privileges. An attacker who already has administrative access to the system software could exploit this flaw to execute unauthorized code at the firmware level. This could lead to a complete compromise of the system's security, including the ability to bypass operating system protections and access sensitive data.
Technical details
An integer overflow vulnerability (CWE-190) exists within the UEFI firmware component of the Intel Slim Bootloader. The flaw is triggered during local access by a high-privileged system software adversary. By exploiting this overflow, an attacker can achieve local code execution within the firmware environment, bypassing higher-level security boundaries. The attack is characterized by low complexity but requires specific 'attack requirements' (preconditions) to be present. Intel has released a firmware update to mitigate this issue, identified by a specific commit hash from January 2026.
Affected products
- Intel Slim Bootloader Versions prior to hash 193129e6a1ea675527670785c8c75ed09b423211 (01/22/2026)
Timeline
- 2026-01-22: patched: Date of the recommended firmware hash fix
- 2026-05-12: disclosed: Initial release of Intel-SA-01425
- 2026-05-12: advisory: NVD publication date