CVE-2025-22853
Improper synchronization in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
Scoring
- Severity
- LOW
- CVSS base score
- 2.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-662
- Published
- 2025-08-12
- Last modified
- 2026-03-13
Affected products
- n/a Intel(R) TDX
Weakness type
Related vulnerabilities
- CVE-2026-13489 — 78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
- CVE-2026-39865 — Axios HTTP/2 Session Cleanup State Corruption Vulnerability
- CVE-2026-28789 — OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling
- CVE-2025-27104 — double eval in For List Iter in Vyper
- CVE-2024-7409 — Qemu: denial of service via improper synchronization in qemu nbd server during socket closure
- CVE-2024-32644 — Evmos' transaction execution not accounting for all state transition after interaction with precompiles