Executive brief
Intel Xeon 6 processors with Trust Domain Extensions (TDX) contain a firmware vulnerability that improper handles protected memory ranges when operating in System Management Mode (SMM). An attacker with privileged access and specialized hardware knowledge could exploit this to escalate privileges and potentially compromise system confidentiality and integrity. Intel has released microcode updates to address this issue.
Technical details
This vulnerability involves improper handling of overlap between protected memory ranges in Intel Xeon 6 processors when TDX operates within SMM. The flaw permits privilege escalation through a local attack vector requiring high complexity and privileged user access combined with specialized internal knowledge. An attacker with SMM-level privileges could exploit the memory range handling logic to escalate privileges and potentially access or modify sensitive data on the affected system. Intel has released microcode updates available via their GitHub repository to mitigate this issue.
Affected products
- Intel Xeon 6 Birch Stream (A06D1, A06E1) and Kaseyville (A06E1)
Timeline
- 2026-08-11: disclosed: Intel security advisory INTEL-SA-01379 published
- 2026-08-11: patched: Microcode updates released via GitHub repository