Description
Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer calculation error in Intel TDX Guest software versions earlier than 0.3.1 allows a local user running in Ring 3 to elevate privileges. The flaw is exploitable with low complexity and without user interaction, and can compromise the confidentiality, integrity, and availability of the system, although the potential impact is rated low due to the limited scope of privilege escalation.

Affected Systems

The vulnerability affects Intel’s TDX Guest software on hosts running any version older than 0.3.1. Only the Intel TDX Guest component is impacted; other Intel software or system components are not directly vulnerable.

Risk and Exploitability

Based on the description, attackers would need local access to a privileged user account to exploit the vulnerability. The CVSS score of 4.6 indicates a low‑to‑medium risk, while the EPSS score of less than 1 % suggests that exploitation is unlikely at present. The flaw is not listed in CISA’s KEV catalog. No special internal knowledge or user interaction is required, so the attack can be executed with minimal effort from a local user with elevated privileges.

Generated by OpenCVE AI on August 12, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install or upgrade Intel TDX Guest software to version 0.3.1 or later.
  • Restrict privileged local user access to the minimum required for essential system operations.
  • Enable and review audit logs for privilege escalation attempts to detect and respond to anomalous activity.

Generated by OpenCVE AI on August 12, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel trust Domain Extensions Guest
CPEs cpe:2.3:a:intel:trust_domain_extensions_guest:*:*:*:*:*:*:*:*
Vendors & Products Intel trust Domain Extensions Guest
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel tdx Guest Software
Vendors & Products Intel
Intel tdx Guest Software

Wed, 12 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Integer Calculation in Intel TDX Guest Software

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-682
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Intel Tdx Guest Software Trust Domain Extensions Guest
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:46:24.853Z

Reserved: 2026-01-13T04:00:20.875Z

Link: CVE-2026-20763

cve-icon Vulnrichment

Updated: 2026-08-12T15:46:21.286Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:17:51.827

Modified: 2026-08-18T15:48:13.780

Link: CVE-2026-20763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:40:53Z

Weaknesses