Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-20105

26
FAUCET Score

CVE-2025-20105 is a high-severity vulnerability affecting UEFI firmware SMM modules on Intel(R) reference platforms, caused by improper input validation that allows for escalation of privilege. This flaw, rated 8.7 High on CVSS, requires high privileges and local access but has low attack complexity and no user interaction, potentially leading to high impacts on system confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
N/AIntel(R) Reference Platforms May Allow An Escalation Of Privilege. System Software Adversary With A Privileged User Combined With A Low Complexity Attack May Enable Local Code Execution. This Result May Potentially Occur Via Local Access When Attack Requirements Are Present Without Special Internal Knowledge And Requires No User Interaction. The Potential Vulnerability May Impact The Confidentiality (High), Integrity (High) And Availability (High) Of The Vulnerable System, Resulting In Subsequent System Confidentiality (High), Integrity (High) And Availability (High) Impacts.
See referencesCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 8th percentile among its peer group of 360 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gcppatch availablevia llm_extracted
View patch

Vendor Advisories (1)

gcpllm-gcp-7b1b5b7121838ce4HIGH

Intel UEFI Reference Firmware March 2026 Security Update

Mar 10, 2026

References

intel.com / content/www/us/en/security-center/advisory/intel-sa-01234.html