PT-2019-4084 · Intel · Intel Core+2
Artem Shishkin
+9
·
Published
2019-11-12
·
Updated
2020-08-24
·
CVE-2019-0117
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families
Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families
Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics
Description
The issue is related to insufficient access control in the protected memory subsystem, which may allow a privileged user to potentially enable information disclosure via local access. This could lead to the exposure of protected information.
Recommendations
For Intel(R) SGX on 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families: update the microcode to ensure proper access control.
For Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families: apply the recommended configuration changes to restrict local access.
For Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics: restrict access to sensitive information until a proper fix is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Core
Intel Sgx
Intel Xeon