Database/Firmware, BMC & network fabric
Intel TDX Guest software: incorrect calculation allows privilege escalation inside the trust domain
Impact
An incorrect calculation in Intel TDX Guest software before 0.3.1, reachable from ring-3 user applications, may allow escalation of privilege. Intel rates the impact low across confidentiality, integrity and availability with no subsequent-system impact, and the attacker already needs to be a privileged local user in the guest. For a confidential-computing GPU tenant this reads as in-guest hardening rather than a break of the trust-domain boundary: nothing in this record implicates the host, the TDX module, or other trust domains. Worth folding into the next guest image refresh, not an emergency window.
Who can reach it
Local privileged user inside the trust domain — Intel describes a system-software adversary with a privileged user running code in the TDX guest. No user interaction, low attack complexity.
What to do
Update Intel TDX Guest software to 0.3.1 or later in your confidential-computing guest images, per Intel-SA-01462, and restart the affected trust domains so they run the new components. Guest-side only — this advisory calls for no host firmware flash and no microcode update.
References
Related entries
- Intel TDX Guest software: incorrect comparison lets a privileged local actor escalate inside a TD guestCVE-2026-20765 · Intel TDX Guest software (ring 3 user applications)Medium
- Dell OpenManage Enterprise: low-privileged user can inject script into the console and expose informationCVE-2026-54793 · Dell OpenManage Enterprise (web console cross-site scripting)Medium
- Lenovo XClarity Controller: Backup/restore password written to an internal XCC log bufferCVE-2021-3473 · Lenovo XClarity ControllerMedium
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesCVE-2017-5698 · Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000Medium
- Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allowsCVE-2019-0117 · Intel SGX protected memory subsystemMedium
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlCVE-2020-24497 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.