CVE-2024-36293 — Improper Access Control in Intel-microcode
Severity
6.8MEDIUMNVD
OSV5.6
EPSS
0.0%
top 92.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateFeb 24
Description
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Packages1 packages
🔴Vulnerability Details
4GHSA▶
GHSA-35p6-x466-363j: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential↗2025-02-13
OSV▶
CVE-2024-36293: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential↗2025-02-12