Potential Information Disclosure Vulnerability in Intel Xeon D Processors with Intel SGX
CVE-2023-43490

5.3MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 March 2024

Summary

A vulnerability exists in some Intel Xeon D processors that utilize Intel Software Guard Extensions (SGX) due to an incorrect calculation in the microcode keying mechanism. This flaw may allow a privileged user with local access to enable the disclosure of sensitive information. The potential for exploited access underscores the need for immediate security measures to protect against unauthorized information retrieval. Users of affected processors should refer to Intel's security advisory for detailed guidance on mitigation.

Affected Version(s)

Intel(R) Xeon(R) D Processors with Intel(R) SGX See references

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.