Time-of-check Time-of-use (TOCTOU) Race Condition in Intel products - CVE-2024-22185
Published: November 18, 2024
Vulnerability identifier: #VU100573
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-22185
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
Intel Alias Checking Trusted Module (ACTM)
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Intel Alias Checking Trusted Module (ACTM)
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Detailed vulnerability description
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local administrator can gain elevated privileges on the target system.
How to mitigate CVE-2024-22185
Install updates from vendor's website.