Information Disclosure Vulnerability in Intel 10th Generation Core Processors
CVE-2020-24491

4.4MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
17 February 2021

Summary

An information disclosure vulnerability exists in certain Intel 10th Generation Core Processors that support Intel Software Guard Extensions (SGX). This vulnerability arises due to debug messages that expose the addresses of memory transactions. A local privileged user could potentially exploit this weakness to gain unauthorized access to sensitive information, thereby increasing the risk of data exposure.

Affected Version(s)

Intel(R) 10th Generation Core Processors supporting SGX See references

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.