PT-2022-15164 · Intel+1 · Intel Processors+1

Published

2022-01-11

·

Updated

2024-11-14

·

CVE-2022-21833

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel processors based on Sunny Cove microarchitecture, including Ice Lake Xeon-SP, Ice Lake D, Gemini Lake, Ice Lake U, Y, and Rocket Lake
Description An elevation-of-privilege issue allows attackers to affect the system. The problem, known as AEPIC Leak, affects the Advanced Programmable Interrupt Controller (APIC) and can be used by attackers to steal confidential information. This issue is related to a defect in the chip architecture that leads to the disclosure of confidential data without using any side channel. The vulnerability affects systems using Software Guard Extensions (SGX) technology.
Recommendations For Intel processors based on Sunny Cove microarchitecture, including Ice Lake Xeon-SP, Ice Lake D, Gemini Lake, Ice Lake U, Y, and Rocket Lake, follow Intel's security guidelines regarding the AEPIC Leak. As a temporary workaround, consider restricting access to the APIC MMIO to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-21833

Affected Products

Intel Processors
Windows