Description
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of the overlap between protected memory ranges for certain Intel Xeon processors when Intel Trusted Domain Extensions (TDX) are used in System Management Mode (SMM) can allow a local attacker to elevate privileges. The vulnerability is classified as type 1260 and type 823 weaknesses and can potentially compromise confidentiality and integrity of the system, with no impact on availability. A high‑complexity attack from an SMM adversary with a privileged user and special internal knowledge, without requiring user interaction, may succeed to gain full system privileges.

Affected Systems

The affected products are Intel Xeon processors that support Intel TDX and are configured to use SMM. No specific firmware or processor model versions are listed beyond the reference to "Intel Xeon 6 processors"; thus any Xeon model that enables TDX with SMM may be vulnerable.

Risk and Exploitability

The CVSS score of 7 indicates a high severity. The EPSS score of 0.00096% indicates extremely low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploit at the time of analysis. The attack vector is inferred to be local, requiring the attacker to already have a privileged user role and a complex exploitation process. Given the high confidentiality and integrity impact, any successful exploitation could give an attacker unrestricted control over the affected system.

Generated by OpenCVE AI on August 14, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Intel firmware update that addresses the TDX memory range handling issue in Xeon processors
  • Restrict or disable SMM for non‑essential services to reduce the privileged surface for potential attackers
  • Implement monitoring of privileged user activity and anomalous memory access patterns to detect attempted exploitation

Generated by OpenCVE AI on August 14, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM
Weaknesses CWE-823
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Moderate


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel xeon
Vendors & Products Intel
Intel xeon

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-1260
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T14:46:56.476Z

Reserved: 2025-04-10T03:00:30.747Z

Link: CVE-2025-31936

cve-icon Vulnrichment

Updated: 2026-08-12T13:33:37.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:43.500

Modified: 2026-08-12T20:54:11.500

Link: CVE-2025-31936

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T16:28:06Z

Links: CVE-2025-31936 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T02:00:15Z

Weaknesses
  • CWE-1260

    Improper Handling of Overlap Between Protected Memory Ranges

  • CWE-823

    Use of Out-of-range Pointer Offset