Insufficient Data Authenticity Verification in Intel Trust Domain Extensions
CVE-2025-31356

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2025-31356?

The vulnerability pertains to insufficient verification of data authenticity in Intel Trust Domain Extensions (TDX), potentially allowing adversaries with privileged access to exploit weaknesses within the hypervisor. This situation can lead to information disclosure, where sensitive data may be exposed through local access without the need for user interaction. While the integrity is somewhat preserved, the compromise in confidentiality poses significant risks to system security. Access to the hypervisor layer increases the attack complexity, indicating that only users with advanced skills could execute such an exploit. For more information, please refer to the official advisory by Intel.

Affected Version(s)

Intel(R) Trust Domain Extensions (Intel(R) TDX) See references

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.