Impact
The vulnerability is an improper authentication flaw in the Intel(R) TDX module that can allow a local attacker with privileged user rights to gain higher privileges and read sensitive data. The flaw can lead to a compromise of confidentiality and integrity, while availability is not affected. Since the flaw requires local access and a high‑complexity attack, it is not trivial, yet the potential impact makes it a serious concern.
Affected Systems
Intel platforms that support the Intel Trusted Domain Extensions (TDX) module are affected. The issue has been observed on some models that implement the TDX module at Ring 0. No specific version information is available, so all platforms with a TDX module should be considered vulnerable until the vendor issues a fix.
Risk and Exploitability
With a CVSS score of 7, the vulnerability represents a moderate to high severity. The EPSS score is less than 1%, indicating a low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is local, requiring possession of an existing privileged account and the execution of a high‑complexity exploit. No user interaction or special internal knowledge is needed, making the threat surface significant for systems that allow privileged users to operate without additional safeguards.
OpenCVE Enrichment