CVE-2024-36293
published 2025-02-12CVE-2024-36293: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable…
PriorityP420medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.24%
15.5th percentile
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250211.1~deb12u1 (bookworm) | intel-microcode 3.20250211.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-02-24·CVSS 5.6
CVE-2024-31068 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
USN-7269-1 fixed vulnerabilities in Intel Microcode. This update provides
the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause
a denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly re
OSV
intel-microcode vulnerabilities
osv·2025-02-17·CVSS 5.6
CVE-2024-31068 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause a
denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly restrict
access. An authenticated local attacker could use this issue to cause a
denial of service. (CVE-2024-39279)
GHSA
GHSA-35p6-x466-363j: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential
ghsa_unreviewed·2025-02-13
CVE-2024-36293 [MEDIUM] CWE-284 GHSA-35p6-x466-363j: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
OSV
CVE-2024-36293: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential
osv·2025-02-12·CVSS 6.8
CVE-2024-36293 [MEDIUM] CVE-2024-36293: Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potential
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-02-24·CVSS 5.3
CVE-2024-39279 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
USN-7269-1 fixed vulnerabilities in Intel Microcode. This update provides
the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause
a denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discover
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-02-17·CVSS 5.3
CVE-2024-36293 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel®
Processors did not properly implement Finite State Machines (FSMs) in
Hardware Logic. A local privileged attacker could use this issue to cause a
denial of service. (CVE-2024-31068)
It was discovered that some Intel® Processors with Intel® SGX did not
properly restrict access to the EDECCSSA user leaf function. A local
authenticated attacker could use this issue to cause a denial of
service. (CVE-2024-36293)
Ke Sun, Alyssa Milburn, Benoit Morgan, and Erik Bjorge discovered that the
UEFI firmware for some Intel® processors did not properly restrict
access. An authenticated local attacker could use this issue to cause a
Red Hat
kernel: microcode_ctl: From CVEorg collector
vendor_redhat·2025-02-12·CVSS 6.8
CVE-2024-36293 [MEDIUM] CWE-284 kernel: microcode_ctl: From CVEorg collector
kernel: microcode_ctl: From CVEorg collector
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
An improper access control vulnerability exists in the linux kernel such that in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Affec
Debian
CVE-2024-36293: intel-microcode - Improper access control in the EDECCSSA user leaf function for some Intel(R) Pro...
vendor_debian·2024·CVSS 6.8
CVE-2024-36293 [MEDIUM] CVE-2024-36293: intel-microcode - Improper access control in the EDECCSSA user leaf function for some Intel(R) Pro...
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.20250211.1)
trixie: resolved (fixed in 3.20250211.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-12
Published