CVE-2025-27572
Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-1420
- Published
- 2026-02-10
- Last modified
- 2026-03-13
Affected products
- n/a TDX
Weakness type
Related vulnerabilities
- CVE-2025-54505 — A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to...
- CVE-2024-36348 — A transient execution vulnerability in some AMD processors may allow a user process to infer the...
- CVE-2024-36349 — A transient execution vulnerability in some AMD processors may allow a user process to infer...