CVE-2020-24489
published 2021-06-09CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
PriorityP339high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.35%
27.5th percentile
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20210608.1 (bookworm) | intel-microcode 3.20210608.1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Mitsubishi Electric Factory Automation Products
cisa_ics·2023-05-02·CVSS 8.8
[HIGH] Mitsubishi Electric Factory Automation Products
ICS Advisory
##
Mitsubishi Electric Factory Automation Products
Release DateMay 02, 2023
Alert CodeICSA-23-122-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Low attack complexity
- Vendor: Mitsubishi Electric
- Equipment: Factory Automation (FA) Products
- Vulnerabilities: Dependency on Vulnerable Third-Party Component
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a malicious attacker to escalate privileges, disclose parameter information in the affected products, and cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Mitsubishi Electric Factory Automation products are affected:
- MELIPC Series
- MI5122-VM: All versions
- MI1002-W: All versions
- MI2012-W: A
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-06-09·CVSS 5.6
CVE-2020-24512 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized
Red Hat
hw: vt-d related privilege escalation
vendor_redhat·2021-06-08·CVSS 8.8
CVE-2020-24489 [HIGH] CWE-459 hw: vt-d related privilege escalation
hw: vt-d related privilege escalation
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
A flaw was found in Intel® VT-d products. Entries from the context cache on some types of context cache invalidations may not be properly invalidated which may allow an authenticated user to potentially enable escalation of privilege via local access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Debian
CVE-2020-24489: intel-microcode - Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated use...
vendor_debian·2020·CVSS 8.8
CVE-2020-24489 [HIGH] CVE-2020-24489: intel-microcode - Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated use...
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20210608.1)
bullseye: resolved (fixed in 3.20210608.1)
forky: resolved (fixed in 3.20210608.1)
sid: resolved (fixed in 3.20210608.1)
trixie: resolved (fixed in 3.20210608.1)
GHSA
GHSA-v4xf-4525-wqq9: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access
ghsa_unreviewed·2022-05-24
CVE-2020-24489 [HIGH] CWE-459 GHSA-v4xf-4525-wqq9: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
OSV
intel-microcode vulnerabilities
osv·2021-06-09·CVSS 5.6
CVE-2020-24489 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized user to
infer the presence of these trivial-data-cache-lines via timing
OSV
CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access
osv·2021-06-09·CVSS 8.8
CVE-2020-24489 [HIGH] CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00442.htmlhttps://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00442.html
2021-06-09
Published