Privilege Escalation Vulnerability in Intel Xeon 6 Processors with TDX
CVE-2025-31936

7HIGH

What is CVE-2025-31936?

This vulnerability involves an improper handling of memory ranges in certain Intel(R) Xeon(R) 6 processors that utilize Intel(R) TDX. An attacker with SMM access could exploit this flaw to escalate their privileges, allowing them to gain unauthorized access and control over the system. The attack is contingent on specific internal knowledge and may also require local access, indicating a heightened complexity for successful exploitation. While it allows for potential confidentiality and integrity impacts, it does not affect system availability.

Affected Version(s)

Intel(R) Xeon(R) 6 processors when using Intel(R) TDX See references

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.