Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-20064

26
FAUCET Score

CVE-2025-20064 details an improper input validation vulnerability within the UEFI FlashUcAcmSmm module on certain Intel reference platforms, which can lead to an escalation of privilege and local code execution. Rated with a CVSS score of 8.7 (High), this vulnerability requires a privileged user and a high complexity attack via local access, but no user interaction, potentially severely impacting system confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
N/AIntel(R) Reference Platforms May Allow An Escalation Of Privilege. System Software Adversary With A Privileged User Combined With A High Complexity Attack May Enable Local Code Execution. This Result May Potentially Occur Via Local Access When Attack Requirements Are Not Present Without Special Internal Knowledge And Requires No User Interaction. The Potential Vulnerability May Impact The Confidentiality (High), Integrity (High) And Availability (High) Of The Vulnerable System, Resulting In Subsequent System Confidentiality (High), Integrity (High) And Availability (High) Impacts.
See referencesCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 11th percentile among its peer group of 160 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gcppatch availablevia llm_extracted
View patch

Vendor Advisories (1)

gcpllm-gcp-7b1b5b7121838ce4HIGH

Intel UEFI Reference Firmware March 2026 Security Update

Mar 10, 2026

References

intel.com / content/www/us/en/security-center/advisory/intel-sa-01234.html