CVE-2025-22889

7.9

Intel · Xeon 6 processor with Intel TDX

A privilege escalation vulnerability in Intel Xeon 6 processors with Intel TDX exists due to improper handling of overlapping protected memory ranges, allowing local authenticated escalation.

Executive summary

An escalation of privilege vulnerability in Intel Xeon 6 processors with Intel TDX poses a significant risk to system security, requiring local access for successful exploitation.

Vulnerability

This vulnerability involves the improper handling of overlapping protected memory ranges (CWE-1260). It requires a highly privileged local user to trigger the escalation of privilege condition.

Business impact

The vulnerability carries a CVSS score of 7.9, indicating a high severity risk. Successful exploitation could allow an already privileged local user to further escalate their access, potentially compromising the integrity and confidentiality of the host environment. This poses a severe threat to systems relying on Intel TDX for secure workload isolation.

Remediation

Immediate Action: Consult the official Intel security advisory at https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01311.html to identify specific firmware or microcode updates and apply them to affected hardware.

Proactive Monitoring: Monitor system logs for unauthorized attempts to perform administrative tasks or unexpected memory access patterns, especially from users with existing high-level privileges.

Compensating Controls: Restrict local system access to essential personnel only and ensure that hardware security features are configured in accordance with vendor hardening guidelines to minimize the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of the Intel TDX environment, organizations should prioritize the review of the referenced Intel security advisory. Administrators must verify their hardware configurations and apply the recommended firmware updates as soon as they become available to prevent potential local privilege escalation.

More Intel CVEs

Sources