PT-2023-9410 · Intel+4 · Intel Software Guard Extensions Sdk+6

Cfir Cohen

+4

·

Publicado

2023-02-15

·

Atualizado

2024-06-15

·

CVE-2022-33196

CVSS v3.1

7.2

Alta

VetorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Intel(R) Xeon(R) Processors (affected versions not specified)
Description The issue concerns incorrect default permissions in some memory controller configurations for Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions. This may allow a privileged user to potentially enable escalation of privilege via local access. The vulnerability is related to Intel Microcode and is associated with default permission settings. Exploitation of the vulnerability could allow an attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-07366
CVE-2022-33196
DLA-3379-1
MGASA-2023-0085
OESA-2023-1548
OESA-2023-1549
OESA-2023-1550
OESA-2023-1553
OESA-2023-1554
OPENSUSE-SU-2024:12704-1
RHSA-2023:5209
ROSA-SA-2023-2228
SUSE-SU-2023:0454-1
SUSE-SU-2023:0455-1
SUSE-SU-2023:0456-1
SUSE-SU-2023:0568-1
USN-5886-1

Produtos afetados

Astra Linux
Intel Microcode
Intel Software Guard Extensions Sdk
Intel Xeon Processors
Linuxmint
Suse
Ubuntu