Unauthorized Error Injection in Intel SGX and TDX on Intel Xeon Processors
CVE-2022-41804
7.2HIGH
Summary
An unauthorized error injection vulnerability exists in the Intel Software Guard Extensions (SGX) and Thread Execution (TDX) for certain Intel Xeon processors. This flaw may allow a privileged user to escalate privileges through local access, potentially compromising system security. Proper mitigation strategies are essential to protect against unauthorized modifications and maintain the integrity of systems utilizing these processors.
Affected Version(s)
Intel(R) Xeon(R) Processors See references
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved