CVE-2024-31068
published 2025-02-12CVE-2024-31068: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via…
PriorityP415medium5.3CVSS 3.1
AVLACHPRHUINSCCNINAH
EPSS
0.22%
12.5th percentile
Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250211.1~deb12u1 (bookworm) | intel-microcode 3.20250211.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv4.05.6MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-02-24·CVSS 5.3
CVE-2024-39279 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
USN-7269-1 fixed vulnerabilities in Intel Microcode. This update provides
the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause
a denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discover
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-02-17·CVSS 5.3
CVE-2024-36293 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause a
denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly restrict
access. An authenticated local attacker could use this issue to cause a
Red Hat
kernel: microcode_ctl: From CVEorg collector
vendor_redhat·2025-02-12·CVSS 5.6
CVE-2024-31068 [MEDIUM] CWE-1245 kernel: microcode_ctl: From CVEorg collector
kernel: microcode_ctl: From CVEorg collector
Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2024-31068: intel-microcode - Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Proces...
vendor_debian·2024·CVSS 5.6
CVE-2024-31068 [MEDIUM] CVE-2024-31068: intel-microcode - Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Proces...
Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.20250211.1)
trixie: resolved (fixed in 3.20250211.1)
OSV
intel-microcode vulnerabilities
osv·2025-02-24·CVSS 5.6
CVE-2024-31068 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
USN-7269-1 fixed vulnerabilities in Intel Microcode. This update provides
the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause
a denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly re
OSV
intel-microcode vulnerabilities
osv·2025-02-17·CVSS 5.6
CVE-2024-31068 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause a
denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly restrict
access. An authenticated local attacker could use this issue to cause a
denial of service. (CVE-2024-39279)
GHSA
GHSA-vgrj-w768-vh7r: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service
ghsa_unreviewed·2025-02-13
CVE-2024-31068 [MEDIUM] CWE-1245 GHSA-vgrj-w768-vh7r: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service
Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.
OSV
CVE-2024-31068: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service
osv·2025-02-12·CVSS 5.6
CVE-2024-31068 [MEDIUM] CVE-2024-31068: Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service
Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-12
Published