Buffer overflow in Intel products - CVE-2025-21096

 

Buffer overflow in Intel products - CVE-2025-21096

Published: August 15, 2025


Vulnerability identifier: #VU114119
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21096
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in the firmware. A local administrator can trigger memory corruption and gain elevated privileges on the target system.


Affected software

Intel 4th Generation Intel Xeon Scalable Processors
Intel 5th Generation Intel Xeon Scalable Processors
Intel Xeon 6 processor with E-cores
Intel Xeon 6 processor with P-cores
Intel Trust Domain Extensions (TDX) module

How to mitigate CVE-2025-21096

Install updates from vendor's website.

Intel Trust Domain Extensions (TDX) module - addressed in versions 1.5.16, 2.0.8

External References

Related Security Bulletins