Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phpq-389w-765c

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 7.9

Описание

Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

EPSS

Процентиль: 0%
0.00005
Низкий

8.3 High

CVSS4

7.9 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.9
nvd
3 месяца назад

Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 4.1
fstec
3 месяца назад

Уязвимость модуля Intel Trust Domain Extensions(TDX) микропрограммного обеспечения процессоров Intel, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 0%
0.00005
Низкий

8.3 High

CVSS4

7.9 High

CVSS3

Дефекты

CWE-362