Vulnerability Allowing Bypass of Intel TDX Protection Mechanism

Google and Intel have disclosed the results (PDF) of their collaborative security audit of Intel TDX 1.5 (Trusted Domain Extensions). The Intel TDX technology enables memory encryption for virtual machines, protecting them from interference and analysis by the host system administrator and physical attacks on hardware. The audit revealed 6 vulnerabilities and 35 non-security-related bugs.

The issues affect Intel Xeon 6 CPUs, as well as 4th and 5th generation Intel Xeon Scalable processors. The vulnerabilities were addressed in yesterday's microcode update. A toolkit for exploiting vulnerabilities in Intel TDX and prototypes of exploits for two vulnerabilities (CVE-2025-30513, CVE-2025-32007) have been published on GitHub.

The most dangerous vulnerability (CVE-2025-30513) allows an untrusted administrator with access to the host system to elevate privileges and fully compromise the security guarantees provided by Intel TDX technology. The vulnerability is caused by a race condition in one of the TDX modules, allowing the protected environment (TD - Trusted Domain) to transition from a migration-supporting state to a state that permits entry into debug mode during virtual machine migration.

The issue is caused by the ability to substitute environment attributes right after their validation but before they are set to an immutable state in the migrated environment. After the debug attribute is set, the host system administrator can monitor the activity of the protected guest system in real time and access the decrypted state of memory.

The vulnerability is relatively easy to exploit, as the administrator can initiate the live migration process of a protected virtual machine at any time. The issue was identified by researchers at Google, who noted discrepancies in how the FSM (Finite State Machine) tracks the state of operations, handles the interruption of the import operation, and changes without reverting to its original state after a failure in the protected environment.

Less critical vulnerabilities:

  • CVE-2025-32007 — integer overflow in the metadata parsing code leading to a leak of 8 KB of decrypted data from the stack of the current logical processor (LP, Logical Processor) during live migration.
  • CVE-2025-32467 — the use of uninitialized variables in some TDX modules may lead to residual information leakage.
  • CVE-2025-27572 — the accumulation of confidential data during speculative instruction execution may lead to information leakage.
  • CVE-2025-27940 — reading from memory outside the allocated buffer may lead to information leakage.
  • CVE-2025-31944 — a race condition that could result in denial of service.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster