Impact
An incorrect comparison in Intel TDX Guest software versions prior to 0.3.1 allows a local, privileged user to elevate privileges. The flaw resides in Ring 3 code and can be triggered by a system software adversary with sufficient permissions, requiring only a low complexity attack and no user interaction. This results in a privilege escalation that risks confidential and integrity data, but the impact is assessed as low for confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Intel TDX Guest software running before version 0.3.1. Users running these older versions of the guest software are susceptible to the described escalation of privilege.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, while an EPSS score below 1% suggests that exploitation is currently rare. The vulnerability requires local access with privileged user rights, limiting the threat to users who already have administrative privileges. It is not listed in the CISA KEV catalog and no public exploits are known at this time. The combination of the low exploitation probability and the requirement for privileged access reduces the overall risk compared to higher‑severity, remotely exploitable flaws.
OpenCVE Enrichment