Privilege Escalation Vulnerability in Intel TDX Module Firmware
CVE-2025-20044

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 August 2025

What is CVE-2025-20044?

An improper locking vulnerability in the Intel TDX Module firmware prior to version 1.5.13 may allow a privileged user to escalate their privileges through local access. This could result in unauthorized actions that compromise the integrity and security of the affected systems, emphasizing the importance of updating to the latest firmware version to mitigate these risks.

Affected Version(s)

Intel(R) TDX Module firmware before version 1.5.13

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.