PT-2024-7027 · Intel · Intel Tdx Module

Published

2024-08-13

·

Updated

2024-08-14

·

CVE-2024-21801

CVSS v4.0

8.3

High

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Intel TDX module software versions prior to 1.5.05.46.698
Description The issue is related to insufficient control flow management in the Intel TDX module software, which can be exploited to potentially enable denial of service via local access. This could allow a privileged user to cause a service disruption.
Recommendations For versions prior to 1.5.05.46.698, update to version 1.5.05.46.698 or later to resolve the issue. As a temporary workaround, consider restricting local access to the Intel TDX module software to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08281
CVE-2024-21801

Affected Products

Intel Tdx Module