PT-2012-2151 · Intel+1 · Intel Trusted Execution Technology (Txt) Sinit Authenticated Code Modules+1

Joanna Rutkowska

+1

·

Published

2012-09-15

·

Updated

2017-12-13

·

CVE-2011-5174

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to 2nd gen i5 i7 SINIT 51.BIN Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to i5 i7 DUAL SINIT 51.BIN Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to i7 QUAD SINIT 51.BIN Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to GM45 GS45 PM45 SINIT 51.BIN Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to Q35 SINIT 51.BIN Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) versions prior to SINIT ACM 1.1
Description A buffer overflow issue exists in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) that allows local users to bypass the Trusted Execution Technology protection mechanism. This issue can be exploited via unspecified vectors, allowing users to perform other unspecified SINIT ACM functions.
Recommendations For Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset, update to 2nd gen i5 i7 SINIT 51.BIN or later. For Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset, update to i5 i7 DUAL SINIT 51.BIN and i7 QUAD SINIT 51.BIN or later. For Mobile Intel GM45, GS45, and PM45 Express Chipset, update to GM45 GS45 PM45 SINIT 51.BIN or later. For Intel Q35 Express Chipsets, update to Q35 SINIT 51.BIN or later. For Intel 5520, 5500, X58, and 7500 Chipsets, update to SINIT ACM 1.1 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5174
SUSE-SU-2017:3276-1
SUSE-SU-2017_3276-1

Affected Products

Intel Trusted Execution Technology (Txt) Sinit Authenticated Code Modules
Suse