CVE-2025-32007 is an out-of-bounds read vulnerability affecting Intel TDX modules prior to version 1.5.24, specifically within Ring 0 of the hypervisor. This medium-severity vulnerability (CVSS 4.4) allows an authorized, privileged local attacker to achieve high confidentiality impact through a low-complexity attack, potentially exposing sensitive data without user interaction. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, including an article from SecurityWeek highlighting its potential for full system compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | TDX | before version tdx module 1.5.24CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.