Security Information Omission in Intel Software Guard Extensions Affecting Data Centers
CVE-2025-35987

4.3MEDIUM

What is CVE-2025-35987?

This vulnerability involves the omission of vital security-related information within Intel's Software Guard Extensions Data Center Attestation Primitives at the kernel level (Ring 0). An authorized attacker with privileged access may exploit this weakness to launch a denial of service or alter data. The exploitation requires local access and specialized internal knowledge, posing significant threats to system integrity and availability. Although the vulnerability does not directly compromise confidentiality, it could facilitate subsequent attacks that jeopardize data integrity.

Affected Version(s)

Intel(R) Software Guard Extensions Data Center Attestation Primitives See references

References

CVSS V4

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.