CVE-2025-27572CWE-1420

Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure

Medium · published February 10, 2026

CVSS v4.0
5.6
EPSS
0%
Percentile
1.2
In the wild
Unconfirmed
What it is

Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

The record
Technical detail
CVSS v4.0
5.6 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00105 · 1.2th percentile
Weakness
CWE-1420 · Exposure of Sensitive Information during Transient Execution
Published
2026-02-10T16:25Z
EPSS history
Timeline
  • 10 FEB 16:25Z
    Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure
    cvelistv5