Executive brief
The Alias Checking Trusted Module in Intel Xeon processors contains a firmware vulnerability that could allow a privileged local attacker to escalate their privileges further, potentially gaining unauthorized access to sensitive system operations. An attacker with existing high privileges and local system access could exploit a flaw in startup code or System Management Mode to bypass security controls, potentially compromising the confidentiality and integrity of data processed by the processor.
Technical details
This vulnerability is an improper access control issue in the firmware of the Alias Checking Trusted Module (ACTM) affecting certain Intel Xeon processors. The root cause lies in inadequate access controls in startup code and System Management Mode (SMM), allowing a privileged local adversary to escalate privileges through a high-complexity attack. Exploitation requires local access and an existing privileged user context, but does not require user interaction or special knowledge. Successful exploitation results in high impact to system confidentiality and integrity. Intel is releasing firmware updates from system manufacturers to mitigate this vulnerability.
Affected products
- Intel Xeon Scalable processor (4th Gen) Affected models with CPU ID 806F7, 806F8
- Intel Xeon Scalable processor (5th Gen) Affected model with CPU ID C06F2
- Intel Xeon6 processor with P-cores Affected models with CPU ID A06D0, A06D1, A06E0, A06E1
- Intel Xeon6 SoC Affected model with CPU ID A06E1
- Intel Xeon6 processor with E-cores Affected model with CPU ID A06F2
Timeline
- 2026-08-11: disclosed: INTEL-SA-01439 advisory published; CVE-2026-20898 disclosed