SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-20716

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege.

HIGH 7.2EPSS 0.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS 4.0
7.2 HIGHCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.09% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
intel/xeon 634 firmware · intel/xeon 636 firmware · intel/xeon 638 firmware · intel/xeon 654 firmware · intel/xeon 656 firmware · intel/xeon 658x firmware · intel/xeon 674x firmware · intel/xeon 676x firmware · intel/xeon 678x firmware · intel/xeon 696x firmware · intel/xeon 698x firmware · intel/xeon 6315p firmware · intel/xeon 6325p firmware · intel/xeon 6333p firmware · intel/xeon 6337p firmware · intel/xeon 6349p firmware · intel/xeon 6353p firmware · intel/xeon 6357p firmware · intel/xeon 6369p firmware · intel/xeon 6377p firmware · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.