CVE-2025-22885: Escalation of Privilege in TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
CVE-2025-22885 is a medium severity vulnerability in the TDX Module firmware caused by improper buffer restrictions. It allows a system software adversary with privileged user access to potentially escalate privileges via a high complexity local attack that requires no user interaction or special internal knowledge. The vulnerability primarily impacts confidentiality (high) and to a lesser extent integrity (low), with no availability impact. There are no known exploits in the wild and no patch information is currently provided.
AI Analysis
Technical Summary
This vulnerability arises from improper buffer restrictions in the TDX Module firmware, enabling escalation of privilege by a system software adversary who already has privileged user access. The attack requires local access and is of high complexity but does not require user interaction or special internal knowledge. The CVSS 4.0 base score is 5.6 (medium severity), reflecting high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation details are available at this time.
Potential Impact
An attacker with privileged user access on the local system could exploit this vulnerability to escalate privileges further, potentially compromising system confidentiality to a high degree and integrity to a low degree. Availability is not affected. There are no known exploits in the wild, indicating limited current active threat.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch or official fix is available, limit privileged user access and monitor for unusual activity consistent with privilege escalation attempts. No vendor advisory or patch links are currently provided.
CVE-2025-22885: Escalation of Privilege in TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Description
CVE-2025-22885 is a medium severity vulnerability in the TDX Module firmware caused by improper buffer restrictions. It allows a system software adversary with privileged user access to potentially escalate privileges via a high complexity local attack that requires no user interaction or special internal knowledge. The vulnerability primarily impacts confidentiality (high) and to a lesser extent integrity (low), with no availability impact. There are no known exploits in the wild and no patch information is currently provided.
CVSS v4.0
Score 5.6medium
Affected software
TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from improper buffer restrictions in the TDX Module firmware, enabling escalation of privilege by a system software adversary who already has privileged user access. The attack requires local access and is of high complexity but does not require user interaction or special internal knowledge. The CVSS 4.0 base score is 5.6 (medium severity), reflecting high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation details are available at this time.
Potential Impact
An attacker with privileged user access on the local system could exploit this vulnerability to escalate privileges further, potentially compromising system confidentiality to a high degree and integrity to a low degree. Availability is not affected. There are no known exploits in the wild, indicating limited current active threat.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch or official fix is available, limit privileged user access and monitor for unusual activity consistent with privilege escalation attempts. No vendor advisory or patch links are currently provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- intel
- Date Reserved
- 2025-01-23T03:59:09.855Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 698b5d5c4b57a58fa119cf0d
Added to database: 02/10/2026, 16:31:24 UTC
Last enriched: 05/28/2026, 21:23:47 UTC
Last updated: 09/10/2026, 22:11:58 UTC
Views: 240
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.