CVE-2026-20885
Received Received - Intake

Improper Authentication in Intel TDX Module

Vulnerability report for CVE-2026-20885, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Intel Corporation

Description

Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel tdx_module *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper authentication in the Intel TDX module for some Intel platforms. It allows an adversary with privileged user access to potentially escalate privileges and disclose information. The attack requires local access, high complexity, and no special internal knowledge or user interaction.

Impact Analysis

This vulnerability may lead to information disclosure and privilege escalation. It can impact system confidentiality and integrity, potentially resulting in low confidentiality and integrity impacts on the affected system.

Mitigation Strategies

Apply Intel's official security updates or patches for the TDX module as soon as they become available. Monitor Intel's security advisories for mitigation guidance and ensure your system software is up to date.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20885. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart