Sensitive Information in Resource Not Removed Before Reuse in Intel TDX Seamldr module - CVE-2024-21850

 

Sensitive Information in Resource Not Removed Before Reuse in Intel TDX Seamldr module - CVE-2024-21850

Published: November 18, 2024


Vulnerability identifier: #VU100572
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21850
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local administrator to escalate privileges on the system.

The vulnerability exists due to sensitive information in resource not removed, which leads to security restrictions bypass and privilege escalation.


Affected software

Intel TDX Seamldr module
HPE ProLiant ML350 Gen11 Server
HPE StoreEasy 1870 Storage
HPE StoreEasy 1870 Performance Storage
HPE StoreEasy 1670 Storage
HPE StoreEasy 1670 Performance Storage
HPE Synergy 480 Gen11 Compute Module
HPE Compute Edge Server e930t
HPE ProLiant ML110 Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant DL380a Gen11
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL110 Gen11
HPE Alletra 4140
HPE Alletra 4120
HPE Alletra 4110
HPE SimpliVity 380 Gen11
HPE StoreEasy 1570 Storage
HPE StoreEasy 1570 Performance
HPE StoreEasy 1470 Storage
HPE StoreEasy 1470 Performance

How to mitigate CVE-2024-21850

Install updates from vendor's website.

Intel TDX Seamldr module - update to 1.5.02.00
HPE ProLiant ML350 Gen11 Server - update to 2.20_05-29-2024
HPE StoreEasy 1870 Storage - update to 2.20_05-29-2024
HPE StoreEasy 1870 Performance Storage - update to 2.20_05-29-2024
HPE StoreEasy 1670 Storage - update to 2.20_05-29-2024
HPE StoreEasy 1670 Performance Storage - update to 2.20_05-29-2024
HPE StoreEasy 1570 Storage - update to 2.20_05-29-2024
HPE StoreEasy 1570 Performance - update to 2.20_05-29-2024
HPE StoreEasy 1470 Storage - update to 2.20_05-29-2024
HPE StoreEasy 1470 Performance - update to 2.20_05-29-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.20_05-29-2024
HPE Compute Edge Server e930t - update to 2.20_05-29-2024
HPE ProLiant ML110 Gen11 - update to 2.20_05-29-2024
HPE ProLiant DL560 Gen11 - update to 2.20_05-29-2024
HPE ProLiant DL380a Gen11 - update to 2.20_05-29-2024
HPE ProLiant DL380 Gen11 Server - update to 2.20_05-29-2024
HPE ProLiant DL360 Gen11 Server - update to 2.20_05-29-2024
HPE ProLiant DL320 Gen11 Server - update to 2.20_05-29-2024
HPE ProLiant DL110 Gen11 - update to 2.20_05-29-2024
HPE Alletra 4140 - update to 2.20_05-29-2024
HPE Alletra 4120 - update to 2.20_05-29-2024
HPE Alletra 4110 - update to 2.20_05-29-2024
HPE SimpliVity 380 Gen11 - update to 2024_1129

External References

Related Security Bulletins