Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-14591 Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 15 May 2025 04:00:00 +0000

Type Values Removed Values Added
Title microcode_ctl: Improper restriction of software interfaces to hardware features
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 14 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 21:15:00 +0000

Type Values Removed Values Added
Description Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.
Weaknesses CWE-1256
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2025-05-15T04:01:18.444Z

Reserved: 2024-10-09T02:59:22.185Z

Link: CVE-2024-48869

cve-icon Vulnrichment

Updated: 2025-05-14T16:55:39.594Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T21:16:02.227

Modified: 2025-05-16T14:43:56.797

Link: CVE-2024-48869

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-13T21:03:22Z

Links: CVE-2024-48869 - Bugzilla

cve-icon OpenCVE Enrichment

No data.