HIGH · 7.2

CVE-2026-20898

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privi...

Vulnerability Description

Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IntelXeon 6315P Firmware-
IntelXeon 6315P-
IntelXeon 6325P Firmware-
IntelXeon 6325P-
IntelXeon 6333P Firmware-
IntelXeon 6333P-
IntelXeon 6337P Firmware-
IntelXeon 6337P-
IntelXeon 6349P Firmware-
IntelXeon 6349P-
IntelXeon 6353P Firmware-
IntelXeon 6353P-
IntelXeon 6357P Firmware-
IntelXeon 6357P-
IntelXeon 6369P Firmware-
IntelXeon 6369P-
IntelXeon 6377P Firmware-
IntelXeon 6377P-
IntelXeon 6503P Firmware-
IntelXeon 6503P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-20898?

CVE-2026-20898 is a vulnerability with a CVSS score of 7.2 (HIGH). Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privi...

How severe is CVE-2026-20898?

CVE-2026-20898 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-20898?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Xeon 6315P Firmware, Intel Xeon 6315P, Intel Xeon 6325P Firmware, Intel Xeon 6325P, Intel Xeon 6333P Firmware.