Arbitrary Memory Overwrite in Google Asylo Products
CVE-2020-8935

5.3MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
15 December 2020

Summary

An arbitrary memory overwrite vulnerability in Google Asylo versions up to 0.6.0 can allow an attacker to exploit the Ecall_restore function. By reallocating untrusted code, the attacker may overwrite sensitive sections of Enclave memory, potentially leading to unauthorized data exposure or system compromise. Users are strongly advised to update their software to the latest version to mitigate this risk.

Affected Version(s)

Asylo <= 0.6.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qinkun Bao (Baidu Security)
Zhaofeng Chen (Baidu Security)
Mingshen Sun (Baidu Security)
Kang Li (Baidu Security)
.