Impact
An improper handling of the overlap between protected memory ranges for certain Intel Xeon processors when Intel Trusted Domain Extensions (TDX) are used in System Management Mode (SMM) can allow a local attacker to elevate privileges. The vulnerability is classified as type 1260 and type 823 weaknesses and can potentially compromise confidentiality and integrity of the system, with no impact on availability. A high‑complexity attack from an SMM adversary with a privileged user and special internal knowledge, without requiring user interaction, may succeed to gain full system privileges.
Affected Systems
The affected products are Intel Xeon processors that support Intel TDX and are configured to use SMM. No specific firmware or processor model versions are listed beyond the reference to "Intel Xeon 6 processors"; thus any Xeon model that enables TDX with SMM may be vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score of 0.00096% indicates extremely low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploit at the time of analysis. The attack vector is inferred to be local, requiring the attacker to already have a privileged user role and a complex exploitation process. Given the high confidentiality and integrity impact, any successful exploitation could give an attacker unrestricted control over the affected system.
OpenCVE Enrichment