MEDIUM · 5.7

CVE-2025-31936

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privil...

Vulnerability Description

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Score

5.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IntelXeon 6337P Firmware-
IntelXeon 6337P-
IntelXeon 6349P Firmware-
IntelXeon 6349P-
IntelXeon 6353P Firmware-
IntelXeon 6353P-
IntelXeon 6357P Firmware-
IntelXeon 6357P-
IntelXeon 6369P Firmware-
IntelXeon 6369P-
IntelXeon 6377P Firmware-
IntelXeon 6377P-
IntelXeon 6503P Firmware-
IntelXeon 6503P-
IntelXeon 6503P-B Firmware-
IntelXeon 6503P-B-
IntelXeon 6505P Firmware-
IntelXeon 6505P-
IntelXeon 6507P Firmware-
IntelXeon 6507P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-31936?

CVE-2025-31936 is a vulnerability with a CVSS score of 5.7 (MEDIUM). Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privil...

How severe is CVE-2025-31936?

CVE-2025-31936 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-31936?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Xeon 6337P Firmware, Intel Xeon 6337P, Intel Xeon 6349P Firmware, Intel Xeon 6349P, Intel Xeon 6353P Firmware.