Improper Initialization in 4th Generation Intel Xeon Scalable Processors and 5th Generation Intel Xeon Scalable processors - CVE-2025-35991
Published: May 15, 2026
Vulnerability identifier: #VU131562
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-35991
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain elevated privileges on the system.
The vulnerability exists due to improper initialization in the UEFI firmware. A local administrator can gain access to sensitive information on the target system.
Affected software
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Cray XD670
5th Generation Intel Xeon Scalable processors
Cray XD670
How to mitigate CVE-2025-35991
Install updates from vendor's website.
Cray XD670 - update to 2.09