CVE-2025-32467 describes an uninitialized variable vulnerability in some TDX Module versions prior to tdx1.5, allowing a privileged local attacker to achieve information disclosure within Ring 0 (hypervisor). This medium-severity vulnerability (CVSS 4.1) requires high attack complexity and privileged user access, potentially leading to high confidentiality impact. While there are no public exploits or KEV entries, the vulnerability has garnered significant community discussion and media coverage, including a SecurityWeek article highlighting its potential for full system compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | TDX Module | before version tdx1.5CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.