PT-2017-16674 · Intel · Intel Core Processor Families+2
Published
2017-07-26
·
Updated
2019-10-03
·
CVE-2017-5691
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intel processors from 6th and 7th Generation Intel Core Processor Families
Intel Xeon E3-1500M v5 and v6 Product Families
Intel Xeon E3-1200 v5 and v6 Product Families
Description
The issue is related to an incorrect check in certain Intel processors, which can allow compromised system firmware to impact SGX security. This occurs due to an incorrect early system state.
Recommendations
For Intel processors from 6th and 7th Generation Intel Core Processor Families, consider disabling SGX functionality until a fix is available.
For Intel Xeon E3-1500M v5 and v6 Product Families, restrict access to system firmware to minimize the risk of exploitation.
For Intel Xeon E3-1200 v5 and v6 Product Families, avoid using compromised system firmware to prevent impact on SGX security.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Core Processor Families
Intel Xeon E3-1200
Intel Xeon E3-1500