CVE-2026-20885
Summary
| CVE | CVE-2026-20885 |
|---|---|
| State | PUBLISHED |
| Assigner | intel |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 17:17:53 UTC |
| Updated | 2026-08-31 14:33:23 UTC |
| Description | Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. |
Risk And Classification
Primary CVSS: v4.0 7 HIGH from [email protected]
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001480000 probability, percentile 0.045550000 (date 2026-08-14)
Problem Types: CWE-287 | Escalation of Privilege, Information Disclosure | CWE-287 Improper Authentication | CWE-287 CWE-287 Improper Authentication
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7 | HIGH | CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7 | HIGH | CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
| 3.1 | [email protected] | Primary | 7.2 | HIGH | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
HighAttack Requirements
PresentPrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
NoneSub Conf.
LowSub Integrity
LowSub Availability
NoneCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Intel | Tdx Module | All | All | All | All |
| Hardware | Intel | Xeon Bronze 3408u | - | All | All | All |
| Hardware | Intel | Xeon Gold 5411n | - | All | All | All |
| Hardware | Intel | Xeon Gold 5412u | - | All | All | All |
| Hardware | Intel | Xeon Gold 5415 | - | All | All | All |
| Hardware | Intel | Xeon Gold 5416s | - | All | All | All |
| Hardware | Intel | Xeon Gold 5418n | - | All | All | All |
| Hardware | Intel | Xeon Gold 5418y | - | All | All | All |
| Hardware | Intel | Xeon Gold 5420 | - | All | All | All |
| Hardware | Intel | Xeon Gold 6414u | - | All | All | All |
| Hardware | Intel | Xeon Gold 6416h | - | All | All | All |
| Hardware | Intel | Xeon Gold 6418h | - | All | All | All |
| Hardware | Intel | Xeon Gold 6421n | - | All | All | All |
| Hardware | Intel | Xeon Gold 6426y | - | All | All | All |
| Hardware | Intel | Xeon Gold 6428n | - | All | All | All |
| Hardware | Intel | Xeon Gold 6430 | - | All | All | All |
| Hardware | Intel | Xeon Gold 6434 | - | All | All | All |
| Hardware | Intel | Xeon Gold 6434h | - | All | All | All |
| Hardware | Intel | Xeon Gold 6438m | - | All | All | All |
| Hardware | Intel | Xeon Gold 6438n | - | All | All | All |
| Hardware | Intel | Xeon Gold 6438y | - | All | All | All |
| Hardware | Intel | Xeon Gold 6442y | - | All | All | All |
| Hardware | Intel | Xeon Gold 6444y | - | All | All | All |
| Hardware | Intel | Xeon Gold 6448h | - | All | All | All |
| Hardware | Intel | Xeon Gold 6448y | - | All | All | All |
| Hardware | Intel | Xeon Gold 6454s | - | All | All | All |
| Hardware | Intel | Xeon Gold 6458q | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8444h | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8450h | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8452y | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8454h | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8458p | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8460h | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8460y | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8461v | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8462y | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8468 | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8468h | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8468v | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8470 | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8470n | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8470q | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8471n | - | All | All | All |
| Hardware | Intel | Xeon Platinum 8480 | - | All | All | All |
| Hardware | Intel | Xeon Silver 4410tm | - | All | All | All |
| Hardware | Intel | Xeon Silver 4410y | - | All | All | All |
| Hardware | Intel | Xeon Silver 4416 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | IntelR Platforms | affected See references | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| intel.com/content/www/us/en/security-center/advisory/intel-sa-01436.html | [email protected] | intel.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.