Impact
An integer calculation error in Intel TDX Guest software versions earlier than 0.3.1 allows a local user running in Ring 3 to elevate privileges. The flaw is exploitable with low complexity and without user interaction, and can compromise the confidentiality, integrity, and availability of the system, although the potential impact is rated low due to the limited scope of privilege escalation.
Affected Systems
The vulnerability affects Intel’s TDX Guest software on hosts running any version older than 0.3.1. Only the Intel TDX Guest component is impacted; other Intel software or system components are not directly vulnerable.
Risk and Exploitability
Based on the description, attackers would need local access to a privileged user account to exploit the vulnerability. The CVSS score of 4.6 indicates a low‑to‑medium risk, while the EPSS score of less than 1 % suggests that exploitation is unlikely at present. The flaw is not listed in CISA’s KEV catalog. No special internal knowledge or user interaction is required, so the attack can be executed with minimal effort from a local user with elevated privileges.
OpenCVE Enrichment