Junglewise Threat Intelligence

CVE-2026-20753: Intel Slim Bootloader integer overflow in UEFI firmware

CVE-2026-20753 · Severity: info · CVSS 8.7 · Published 2026-05-12

Vendors: Intel.

Executive brief

A vulnerability in the Intel Slim Bootloader, which is responsible for initializing hardware and launching the operating system, could allow an attacker to gain higher-level system privileges. An attacker who already has administrative access to the system software could exploit this flaw to execute unauthorized code at the firmware level. This could lead to a complete compromise of the system's security, including the ability to bypass operating system protections and access sensitive data.

Technical details

An integer overflow vulnerability (CWE-190) exists within the UEFI firmware component of the Intel Slim Bootloader. The flaw is triggered during local access by a high-privileged system software adversary. By exploiting this overflow, an attacker can achieve local code execution within the firmware environment, bypassing higher-level security boundaries. The attack is characterized by low complexity but requires specific 'attack requirements' (preconditions) to be present. Intel has released a firmware update to mitigate this issue, identified by a specific commit hash from January 2026.

Affected products

  • Intel Slim Bootloader Versions prior to hash 193129e6a1ea675527670785c8c75ed09b423211 (01/22/2026)

Timeline

  • 2026-01-22: patched: Date of the recommended firmware hash fix
  • 2026-05-12: disclosed: Initial release of Intel-SA-01425
  • 2026-05-12: advisory: NVD publication date

References