Impact
This vulnerability arises from the insecure storage of sensitive information in the Intel TDX module within Ring 0 on certain Intel platforms. The flaw allows a privileged local user to access data that should be protected, resulting in a high confidentiality impact while integrity and availability remain unaffected.
Affected Systems
The affected systems are Intel platforms that incorporate the Intel TDX module; the CNA did not specify product or version details, so any system using TDX at the time of this advisory is potentially impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attack conditions require local access by a privileged user and a high complexity attack, but no special internal knowledge or user interaction is needed. The most likely vector is a local privilege escalation within the Trust Domain that can read stored data in memory.
OpenCVE Enrichment