Improper Initialization in 4th Generation Intel Xeon Scalable Processors and 5th Generation Intel Xeon Scalable processors - CVE-2025-35991

 

Improper Initialization in 4th Generation Intel Xeon Scalable Processors and 5th Generation Intel Xeon Scalable processors - CVE-2025-35991

Published: May 15, 2026


Vulnerability identifier: #VU131562
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-35991
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain elevated privileges on the system.

The vulnerability exists due to improper initialization in the UEFI firmware. A local administrator can gain access to sensitive information on the target system.


Affected software

4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Cray XD670

How to mitigate CVE-2025-35991

Install updates from vendor's website.

Cray XD670 - update to 2.09

External References

Related Security Bulletins