CVE-2020-24489Incomplete Cleanup in Intel-microcode

CWE-459Incomplete Cleanup8 documents7 sources
Severity
8.8HIGHNVD
OSV5.6
EPSS
0.1%
top 79.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 2

Description

Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20210608.1 (bookworm)

Also affects: Debian Linux 10.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-v4xf-4525-wqq9: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access2022-05-24
OSV
intel-microcode vulnerabilities2021-06-09
OSV
CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access2021-06-09

📋Vendor Advisories

4
CISA ICS
Mitsubishi Electric Factory Automation Products2023-05-02
Ubuntu
Intel Microcode vulnerabilities2021-06-09
Red Hat
hw: vt-d related privilege escalation2021-06-08
Debian
CVE-2020-24489: intel-microcode - Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated use...2020