CVE-2025-31936
Awaiting Analysis Awaiting Analysis - Queue

Privilege Escalation in Intel Xeon 6 Processors via SMM

Vulnerability report for CVE-2025-31936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-09-18

Assigner: Intel Corporation

Description

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-09-18
Generated
2026-09-21
AI Q&A
2026-08-11
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 73 associated CPEs
Vendor Product Version / Range
intel xeon_6337p_firmware *
intel xeon_6349p_firmware *
intel xeon_6353p_firmware *
intel xeon_6357p_firmware *
intel xeon_6369p_firmware *
intel xeon_6377p_firmware *
intel xeon_6503p_firmware *
intel xeon_6503p-b_firmware *
intel xeon_6505p_firmware *
intel xeon_6507p_firmware *
intel xeon_6511p_firmware *
intel xeon_6513p-b_firmware *
intel xeon_6515p_firmware *
intel xeon_6516p-b_firmware *
intel xeon_6517p_firmware *
intel xeon_6518p-b_firmware *
intel xeon_6520p_firmware *
intel xeon_6521p_firmware *
intel xeon_6523p-b_firmware *
intel xeon_6527p_firmware *
intel xeon_6530p_firmware *
intel xeon_6532p-b_firmware *
intel xeon_6533p-b_firmware *
intel xeon_6543p-b_firmware *
intel xeon_6544p-b_firmware *
intel xeon_6546p-b_firmware *
intel xeon_6548p-b_firmware *
intel xeon_6553p-b_firmware *
intel xeon_6556p-b_firmware *
intel xeon_6563p-b_firmware *
intel xeon_6706p-b_firmware *
intel xeon_6714p_firmware *
intel xeon_6716p-b_firmware *
intel xeon_6718p-b_firmware *
intel xeon_6724p_firmware *
intel xeon_6725p_firmware *
intel xeon_6726p-b_firmware *
intel xeon_6728p_firmware *
intel xeon_6730p_firmware *
intel xeon_6731p_firmware *
intel xeon_6732p_firmware *
intel xeon_6736p_firmware *
intel xeon_6737p_firmware *
intel xeon_6738p_firmware *
intel xeon_6740p_firmware *
intel xeon_6741p_firmware *
intel xeon_6745p_firmware *
intel xeon_6747p_firmware *
intel xeon_6748p_firmware *
intel xeon_6756p-b_firmware *
intel xeon_6760p_firmware *
intel xeon_6761p_firmware *
intel xeon_6766p-b_firmware *
intel xeon_6767p_firmware *
intel xeon_6768p_firmware *
intel xeon_6768p-b_firmware *
intel xeon_6774p_firmware *
intel xeon_6776p_firmware *
intel xeon_6776p-b_firmware *
intel xeon_6781p_firmware *
intel xeon_6787p_firmware *
intel xeon_6788p_firmware *
intel xeon_6944p_firmware *
intel xeon_6952p_firmware *
intel xeon_6960p_firmware *
intel xeon_6962p_firmware *
intel xeon_6972p_firmware *
intel xeon_6978p_firmware *
intel xeon_6979p_firmware *
intel xeon_6980p_firmware *
intel xeon_6315p_firmware *
intel xeon_6325p_firmware *
intel xeon_6333p_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1260 The product allows address regions to overlap, which can result in the bypassing of intended memory protection.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of protected memory ranges in some Intel Xeon 6 processors when using Intel Trust Domain Extensions (TDX) within System Management Mode (SMM). An attacker with privileged access and special internal knowledge could exploit this to escalate privileges.

Detection Guidance

Detection requires specialized knowledge of Intel TDX and SMM environments. No standard commands are provided in the CVE details. Consult Intel's official documentation or security advisories for detection methods.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain higher privileges on the system, potentially leading to unauthorized access or control. It may impact system confidentiality and integrity but does not directly affect availability.

Compliance Impact

This vulnerability may impact confidentiality and integrity of the system, which could lead to unauthorized access or data breaches. Such breaches could potentially violate compliance requirements under GDPR or HIPAA if sensitive data is exposed or altered.

Mitigation Strategies

Apply Intel's official firmware updates or patches for affected Xeon 6 processors. Disable Intel TDX in SMM if not required. Monitor Intel's security advisories for further guidance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-31936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart