CVE-2023-42776

Severity
5.5MEDIUM
EPSS
0.1%
top 72.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateOct 24

Description

Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 2.0 | Impact: 1.4

Affected Packages2 packages

CVEListV5intel(r)_sgx_dcap_software_for_windowsbefore version 1.19.100.3
NVDintel/sgx_dcap< 1.19.100.3

🔴Vulnerability Details

2
GHSA
GHSA-8gq7-5hvw-m2r3: Improper input validation in some Intel(R) SGX DCAP software for Windows before version 12024-10-24
CVEList
CVE-2023-42776: Improper input validation in some Intel(R) SGX DCAP software for Windows before version 12024-02-14
CVE-2023-42776 (MEDIUM CVSS 5.5) | Improper input validation in some I | cvebase.io