CVE-2022-33972
published 2023-02-16CVE-2022-33972: Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially…
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.22%
12.5th percentile
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20230214.1 (bookworm) | intel-microcode 3.20230214.1 (bookworm) |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2023-02-27·CVSS 6.8
CVE-2022-21216 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Erik C. Bjorge discovered that some Intel(R) Atom and Intel Xeon Scalable
Processors did not properly implement access controls for out-of-band
management. This may allow a privileged network-adjacent user to potentially
escalate privileges. (CVE-2022-21216)
Cfir Cohen, Erdem Aktas, Felix Wilhelm, James Forshaw, Josh Eads, Nagaraju
Kodalapura Nagabhushana Rao, Przemyslaw Duda, Liron Shacham and Ron Anderson
discovered that some Intel(R) Xeon(R) Processors used incorrect default
permissions in some memory controller configurations when using Intel(R)
Software Guard Extensions. This may allow a privileged local user to potentially
escalate privileges. (CVE-2022-33196)
It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable Processors
did not pr
OSV
CVE-2022-33972: Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potent
osv·2023-02-16·CVSS 4.4
CVE-2022-33972 [MEDIUM] CVE-2022-33972: Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potent
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
GHSA
GHSA-7h77-h852-j28h: Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potent
ghsa_unreviewed·2023-02-16
CVE-2022-33972 [MEDIUM] CWE-682 GHSA-7h77-h852-j28h: Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potent
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 7.5
CVE-2022-33972 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Erik C. Bjorge discovered that some Intel(R) Atom and Intel Xeon Scalable
Processors did not properly implement access controls for out-of-band
management. This may allow a privileged network-adjacent user to potentially
escalate privileges. (CVE-2022-21216)
Cfir Cohen, Erdem Aktas, Felix Wilhelm, James Forshaw, Josh Eads, Nagaraju
Kodalapura Nagabhushana Rao, Przemyslaw Duda, Liron Shacham and Ron Anderson
discovered that some Intel(R) Xeon(R) Processors used incorrect default
permissions in some memory controller configurations when using Intel(R)
Software Guard Extensions. This may allow a privileged local user to potentially
escalate privileges. (CVE-2022-33196)
It was discovered
Red Hat
kernel: Intel firmware update for incorrect calculation in microcode keying mechanism
vendor_redhat·2023-02-16·CVSS 6.1
CVE-2022-33972 [MEDIUM] kernel: Intel firmware update for incorrect calculation in microcode keying mechanism
kernel: Intel firmware update for incorrect calculation in microcode keying mechanism
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
A flaw was found in the Linux kernel. 3rd Generation Intel Xeon Scalable Processors may allow information disclosure. This issue could allow a privileged user to enable information disclosure via local access.
Statement: Red Hat has very limited visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content. In most cases, it merely acts as a release vehicle between the thi
Debian
CVE-2022-33972: intel-microcode - Incorrect calculation in microcode keying mechanism for some 3rd Generation Inte...
vendor_debian·2022·CVSS 6.1
CVE-2022-33972 [MEDIUM] CVE-2022-33972: intel-microcode - Incorrect calculation in microcode keying mechanism for some 3rd Generation Inte...
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230214.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
forky: resolved (fixed in 3.20230214.1)
sid: resolved (fixed in 3.20230214.1)
trixie: resolved (fixed in 3.20230214.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published