PT-2022-15164 · Intel+1 · Intel Processors+1
Published
2022-01-11
·
Updated
2024-11-14
·
CVE-2022-21833
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel processors based on Sunny Cove microarchitecture, including Ice Lake Xeon-SP, Ice Lake D, Gemini Lake, Ice Lake U, Y, and Rocket Lake
Description
An elevation-of-privilege issue allows attackers to affect the system. The problem, known as AEPIC Leak, affects the Advanced Programmable Interrupt Controller (APIC) and can be used by attackers to steal confidential information. This issue is related to a defect in the chip architecture that leads to the disclosure of confidential data without using any side channel. The vulnerability affects systems using Software Guard Extensions (SGX) technology.
Recommendations
For Intel processors based on Sunny Cove microarchitecture, including Ice Lake Xeon-SP, Ice Lake D, Gemini Lake, Ice Lake U, Y, and Rocket Lake, follow Intel's security guidelines regarding the AEPIC Leak. As a temporary workaround, consider restricting access to the APIC MMIO to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Processors
Windows