Impact
This vulnerability arises from insufficient granularity of access control in a subsystem of Intel Xeon 6 Scalable processors that support Intel Trust Domain Extensions (TXD). The flaw permits an authorized adversary possessing an authenticated user account to access data that should be restricted, potentially leading to an information disclosure. The impact on the vulnerable system itself is listed as no direct confidentiality loss, but once the attacker gains data, the overall system confidentiality could be considered high, with no reported integrity or availability impact.
Affected Systems
Affected systems include Intel Xeon 6 Scalable processors integrated with Intel Trust Domain Extensions. The advisory does not enumerate specific firmware or microcode versions, but any system incorporating this processor family and utilizing TDX is potentially susceptible.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate base severity, while the EPSS is reported as < 1%, suggesting a very low anticipated exploitation likelihood at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, further implying limited current exploitation. However, the attack requires local access and high‑complexity steps, so the likelihood remains low. Nevertheless, the potential for high‑impact confidentiality exposure warrants monitoring or mitigation as advised by Intel.
OpenCVE Enrichment