Buffer overflow in Intel products - CVE-2025-21096
Published: August 15, 2025
Vulnerability identifier: #VU114119
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21096
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the firmware. A local administrator can trigger memory corruption and gain elevated privileges on the target system.
Affected software
Intel 4th Generation Intel Xeon Scalable Processors
Intel 5th Generation Intel Xeon Scalable Processors
Intel Xeon 6 processor with E-cores
Intel Xeon 6 processor with P-cores
Intel Trust Domain Extensions (TDX) module
Intel 5th Generation Intel Xeon Scalable Processors
Intel Xeon 6 processor with E-cores
Intel Xeon 6 processor with P-cores
Intel Trust Domain Extensions (TDX) module
How to mitigate CVE-2025-21096
Install updates from vendor's website.
Intel Trust Domain Extensions (TDX) module - addressed in versions 1.5.16, 2.0.8