Impact
The flaw arises from inadequate verification of data authenticity inside the Intel Trust Domain Extensions (TDX) hypervisor, allowing an attacker with privileged user access to read protected memory. The result is a high confidentiality impact due to potential data exposure, with a low integrity effect and no change to availability. The weakness is classified as CWE-345.
Affected Systems
Manufactured by Intel, the affected component is the Intel Trust Domain Extensions (TDX) hypervisor. No specific product version numbers are listed in the advisory, meaning all deployments of TDX that run unpatched may be susceptible. The vulnerability requires local access with privileged user rights to the system software running within the TDX environment.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not recorded in the CISA KEV catalog. The attack is local and requires high complexity, so an experienced adversary would need to control a privileged account and interact with the hypervisor environment. No user interaction is required beyond the elevated privileges.
OpenCVE Enrichment