Escalation of Privilege Vulnerability in Intel TDX Guest Software
CVE-2026-20765

4.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-20765?

An improperly conducted comparison in certain versions of Intel(R) TDX Guest software prior to 0.3.1 can allow for an escalation of privilege. An adversary with system software access and a privileged user could exploit this vulnerability through a low complexity attack, possibly gaining elevated privileges. The vulnerability necessitates local access and does not require extensive knowledge or user interaction, which can severely impact system integrity and accessibility.

Affected Version(s)

Intel(R) TDX Guest software before version 0.3.1

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.