PT-2017-16674 · Intel · Intel Core Processor Families+2

Published

2017-07-26

·

Updated

2019-10-03

·

CVE-2017-5691

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel processors from 6th and 7th Generation Intel Core Processor Families Intel Xeon E3-1500M v5 and v6 Product Families Intel Xeon E3-1200 v5 and v6 Product Families
Description The issue is related to an incorrect check in certain Intel processors, which can allow compromised system firmware to impact SGX security. This occurs due to an incorrect early system state.
Recommendations For Intel processors from 6th and 7th Generation Intel Core Processor Families, consider disabling SGX functionality until a fix is available. For Intel Xeon E3-1500M v5 and v6 Product Families, restrict access to system firmware to minimize the risk of exploitation. For Intel Xeon E3-1200 v5 and v6 Product Families, avoid using compromised system firmware to prevent impact on SGX security. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-5691

Affected Products

Intel Core Processor Families
Intel Xeon E3-1200
Intel Xeon E3-1500