CVE-2021-33117
published 2022-05-12CVE-2021-33117: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.31%
22.6th percentile
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20220207.1 (bookworm) | intel-microcode 3.20220207.1 (bookworm) |
| intel | bios | < mr7 | mr7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Intel Microcode vulnerabilities
osv·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Intel Microcode vulnerabilities
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to ex
OSV
intel-microcode vulnerabilities
osv·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)
GHSA
GHSA-fmf3-xj8j-qrw9: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall
ghsa_unreviewed·2022-05-13
CVE-2021-33117 [MEDIUM] GHSA-fmf3-xj8j-qrw9: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
OSV
CVE-2021-33117: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall
osv·2022-05-12·CVSS 5.5
CVE-2021-33117 [MEDIUM] CVE-2021-33117: Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentiall
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on m
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local a
Red Hat
hw: cpu: information disclosure in Intel® Xeon® Scalable Processors
vendor_redhat·2022-05-10·CVSS 5.5
CVE-2021-33117 [MEDIUM] CWE-212 hw: cpu: information disclosure in Intel® Xeon® Scalable Processors
hw: cpu: information disclosure in Intel® Xeon® Scalable Processors
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
A flaw was found in hw. Improper access control for some third-generation Intel(R) Xeon(R) Scalable processors before BIOS version MR7 may potentially allow a local attacker to enable information disclosure via local access.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third
Debian
CVE-2021-33117: intel-microcode - Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Proces...
vendor_debian·2021·CVSS 5.5
CVE-2021-33117 [MEDIUM] CVE-2021-33117: intel-microcode - Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Proces...
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolved (fixed in 3.20220207.1)
trixie: resolved (fixed in 3.20220207.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-12
Published