Unauthorized Error Injection in Intel SGX and TDX on Intel Xeon Processors
CVE-2022-41804

7.2HIGH

Key Information:

Vendor
Debian
Vendor
CVE Published:
11 August 2023

Summary

An unauthorized error injection vulnerability exists in the Intel Software Guard Extensions (SGX) and Thread Execution (TDX) for certain Intel Xeon processors. This flaw may allow a privileged user to escalate privileges through local access, potentially compromising system security. Proper mitigation strategies are essential to protect against unauthorized modifications and maintain the integrity of systems utilizing these processors.

Affected Version(s)

Intel(R) Xeon(R) Processors See references

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.