CVE-2024-21820Incorrect Default Permissions in Intel-microcode

Severity
8.5HIGHNVD
EPSS
0.0%
top 97.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateDec 11

Description

Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20241112.1~deb12u1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2024-12-11
GHSA
GHSA-643q-8gx3-hf55: Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user2024-11-13
OSV
CVE-2024-21820: Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user2024-11-13

📋Vendor Advisories

2
Ubuntu
Intel Microcode vulnerabilities2024-12-11
Debian
CVE-2024-21820: intel-microcode - Incorrect default permissions in some Intel(R) Xeon(R) processor memory controll...2024