Insecure Information Storage in Intel TDX Module Affects Intel Platforms
CVE-2026-20705

6.8MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-20705?

The Intel TDX module in certain Intel platforms has a vulnerability that allows for insecure storage of sensitive information within Ring 0: Trust Domain. This flaw can lead to potential information disclosure, allowing an adversary with system software privileges to exploit this vulnerability under specific attack conditions. Notably, the attack can occur through local access without requiring special internal knowledge or user interaction. The implications include significant concerns regarding data confidentiality, underscoring the need for enhanced security measures.

Affected Version(s)

Intel(R) platform See references

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.