Junglewise Threat Intelligence

CVE-2026-20760: Intel Processor microcode privilege escalation in Ring 0

CVE-2026-20760 · Severity: info · CVSS 6.8 · Published 2026-08-11

Technologies: Intel Core Ultra Processors Series 2, Intel Core Ultra Processors Series 3. Vendors: Intel.

Executive brief

Intel processors contain a flaw in their microcode that allows an authorized local user with elevated privileges to escalate their access further or cause system denial of service through improper handling of protected memory ranges. This affects Intel's latest mobile processors (Core Ultra Series 2 and 3) and requires a firmware update from system manufacturers to remediate.

Technical details

A microcode vulnerability in Intel processors improperly handles overlaps between protected memory ranges within Ring 0 (hypervisor/kernel context), potentially allowing privilege escalation. The vulnerability requires local access and a low-complexity attack from an authorized user with existing elevated privileges (PR:L). Attack vector is local (AV:L) with no special attack requirements or user interaction needed. An attacker can achieve high impact on system availability (VA:H). Intel has released microcode updates via their public GitHub repository (intel/Intel-Linux-Processor-Microcode-Data-Files) to address this issue; system manufacturers must provide firmware updates incorporating these patches.

Affected products

  • Intel Core Ultra Processors Series 2 Lunar Lake, Arrow Lake Mobile platforms
  • Intel Core Ultra Processors Series 3 Panther Lake Mobile platform

Timeline

  • 2026-08-11: disclosed: Intel-SA-01441 advisory published
  • 2026-08-11: patched: Microcode updates released on Intel's GitHub repository

References

Related threats