Vulnerability Description
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Tdx Module | <= 1.5.28 |
| Intel | Xeon Bronze 3408U | - |
| Intel | Xeon Gold 5411N | - |
| Intel | Xeon Gold 5412U | - |
| Intel | Xeon Gold 5415 | - |
| Intel | Xeon Gold 5416S | - |
| Intel | Xeon Gold 5418N | - |
| Intel | Xeon Gold 5418Y | - |
| Intel | Xeon Gold 5420 | - |
| Intel | Xeon Gold 6414U | - |
| Intel | Xeon Gold 6416H | - |
| Intel | Xeon Gold 6418H | - |
| Intel | Xeon Gold 6421N | - |
| Intel | Xeon Gold 6426Y | - |
| Intel | Xeon Gold 6428N | - |
| Intel | Xeon Gold 6430 | - |
| Intel | Xeon Gold 6434 | - |
| Intel | Xeon Gold 6434H | - |
| Intel | Xeon Gold 6438M | - |
| Intel | Xeon Gold 6438N | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-20885?
CVE-2026-20885 is a vulnerability with a CVSS score of 7.2 (HIGH). Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary wi...
How severe is CVE-2026-20885?
CVE-2026-20885 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-20885?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Tdx Module, Intel Xeon Bronze 3408U, Intel Xeon Gold 5411N, Intel Xeon Gold 5412U, Intel Xeon Gold 5415.