CVE-2024-33607: Medium severity Intel TDX module software vulnerability
Published Aug 12, 2025
·Updated
Out-of-bounds read in some Intel(R) TDX module software before version TDX1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
2 affected components
Intel TDX module software<TDX_1.5.07.00.774
Intel TDX module<1.5.07.00.774
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intel(R) TDX module softwareto a version that resolves this vulnerability.Fixed in TDX_1.5.07.00.774
Event History
Aug 12, 2025
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33607?
CVE-2024-33607 has a medium severity level due to the potential for information disclosure.
2
How do I fix CVE-2024-33607?
To fix CVE-2024-33607, upgrade Intel TDX module software to version TDX_1.5.07.00.774 or later.
3
Who is affected by CVE-2024-33607?
CVE-2024-33607 affects users of Intel TDX module software versions prior to TDX_1.5.07.00.774.
4
What type of vulnerability is CVE-2024-33607?
CVE-2024-33607 is classified as an out-of-bounds read vulnerability.
5
Can CVE-2024-33607 be exploited remotely?
No, CVE-2024-33607 requires local access for exploitation.