CVE-2025-31356 PUBLISHED

Assigner: intel
Reserved: 15.04.2025 Published: 11.08.2026 Updated: 11.08.2026

Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.6

Product Status

Vendor n/a
Product Intel(R) Trust Domain Extensions (Intel(R) TDX)
Versions Default: unaffected
  • Version See references is affected

References

Problem Types

  • Information Disclosure
  • Insufficient Verification of Data Authenticity CWE