PT-2019-5580 · Intel · Intel Processors
Published
2019-12-11
·
Updated
2023-02-02
·
CVE-2019-14607
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Intel Processors (affected versions not specified)
Description
The issue is related to insufficient checking of exceptional states in Intel processor microcode, potentially allowing an authenticated user to partially escalate privileges, cause a denial of service, and/or disclose information via local access. This vulnerability can be exploited through manipulation of the dynamic voltage and frequency scaling mechanism in the CPU, potentially damaging data cell contents, including those used in Intel SGX isolated enclaves. The attack, known as Plundervolt, may enable a local user to gain elevated privileges, cause a service disruption, and access protected data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Processors