Buffer Over-read Vulnerability in Windows TDX.sys by Microsoft
CVE-2025-60720
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-60720?
A buffer over-read vulnerability exists in Windows TDX.sys, which could potentially allow an authorized attacker to gain elevated privileges locally. By exploiting this flaw, an attacker may gain unauthorized access to sensitive information or further manipulate system functions, posing significant security risks.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8594
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8027
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6575