Junglewise Threat Intelligence

CVE-2026-20763: Intel TDX Guest Software privilege escalation in Ring 3

CVE-2026-20763 · Severity: medium · CVSS 4.2 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel's Trust Domain Extensions (TDX) Guest software provides trusted execution environment capabilities for sensitive workloads. The vulnerability allows a privileged local user to escalate privileges within Ring 3 user applications through incorrect calculation logic, potentially compromising the confidentiality and integrity of the affected system. A patch to version 0.3.1 or later is available.

Technical details

The vulnerability is a privilege escalation flaw in Intel TDX Guest software versions before 0.3.1, stemming from incorrect calculation logic in Ring 3 (user application) context. The attack vector is local, requiring high privileges (PR:H) with low attack complexity (AC:L) and no user interaction (UI:N). An adversary with elevated system software privileges can exploit this to escalate privileges within user applications, resulting in low impacts to confidentiality, integrity, and availability of the vulnerable system. The mitigation is to update Intel TDX Guest software to version 0.3.1 or later, available on GitHub.

Affected products

  • Intel TDX Guest Software before 0.3.1

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Update to version 0.3.1 or later

References

Related threats