PT-2023-9410 · Intel+4 · Intel Software Guard Extensions Sdk+6

Cfir Cohen

+4

·

Published

2023-02-15

·

Updated

2024-06-15

·

CVE-2022-33196

CVSS v3.1

7.2

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Intel(R) Xeon(R) Processors (affected versions not specified)
Description The issue concerns incorrect default permissions in some memory controller configurations for Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions. This may allow a privileged user to potentially enable escalation of privilege via local access. The vulnerability is related to Intel Microcode and is associated with default permission settings. Exploitation of the vulnerability could allow an attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07366
CVE-2022-33196
DLA-3379-1
MGASA-2023-0085
OESA-2023-1548
OESA-2023-1549
OESA-2023-1550
OESA-2023-1553
OESA-2023-1554
OPENSUSE-SU-2024:12704-1
RHSA-2023:5209
ROSA-SA-2023-2228
SUSE-SU-2023:0454-1
SUSE-SU-2023:0455-1
SUSE-SU-2023:0456-1
SUSE-SU-2023:0568-1
USN-5886-1

Affected Products

Astra Linux
Intel Microcode
Intel Software Guard Extensions Sdk
Intel Xeon Processors
Linuxmint
Suse
Ubuntu