CVE-2019-14566Improper Input Validation in Intel 2019.2 IPU Intel SGX

Severity
7.8HIGHNVD
EPSS
0.1%
top 67.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 24

Description

Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5intel/2019.2_ipu_intel_sgxSee provided reference

🔴Vulnerability Details

2
GHSA
GHSA-77jw-45f6-38qv: Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure2022-05-24
CVEList
CVE-2019-14566: Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure2019-11-14
CVE-2019-14566 — Improper Input Validation in Intel | cvebase