Incorrect default permissions in Intel products - CVE-2024-21820
Published: December 27, 2024
Vulnerability identifier: #VU101942
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21820
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions in some Intel Xeon processor memory controller configurations when using Intel SGX. A local user escalate privileges on the system.
Affected software
3rd Generation Intel Xeon Scalable Processors
Intel Xeon D Processors
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Precision 7960 Tower
Precision 5860 Tower
Precision 7960 XL Rack
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE Compute Edge Server e930t
HPE Synergy 480 Gen11 Compute Module
HPE ProLiant DL110 Gen11
HPE Alletra 4140
HPE Alletra 4120
HPE Alletra 4110
HPE StoreEasy 1670 Storage
HPE StoreEasy 1670 Performance Storage
HPE StoreEasy 1870 Storage
HPE StoreEasy 1870 Performance Storage
HPE SimpliVity 380 Gen11
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debugsource
ucode-intel-debuginfo
Precision 7960 Rack
HPE StoreEasy 1570 Performance
HPE StoreEasy 1470 Storage
HPE StoreEasy 1470 Performance
HPE StoreEasy 1570 Storage
Apstra
Intel Xeon D Processors
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Precision 7960 Tower
Precision 5860 Tower
Precision 7960 XL Rack
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE Compute Edge Server e930t
HPE Synergy 480 Gen11 Compute Module
HPE ProLiant DL110 Gen11
HPE Alletra 4140
HPE Alletra 4120
HPE Alletra 4110
HPE StoreEasy 1670 Storage
HPE StoreEasy 1670 Performance Storage
HPE StoreEasy 1870 Storage
HPE StoreEasy 1870 Performance Storage
HPE SimpliVity 380 Gen11
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debugsource
ucode-intel-debuginfo
Precision 7960 Rack
HPE StoreEasy 1570 Performance
HPE StoreEasy 1470 Storage
HPE StoreEasy 1470 Performance
HPE StoreEasy 1570 Storage
Apstra
How to mitigate CVE-2024-21820
Install updates from vendor's website.
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20241112.0ubuntu0.20.04.1, 3.20241112.0ubuntu0.22.04.1, 3.20241112.0ubuntu0.24.04.1, 3.20241112.0ubuntu0.24.10.1
microcode_ctl - addressed in versions 2.1-58.5.fc39, 2.1-61.5.fc40, 2.1-67.fc41
Precision 7960 Tower - update to 2.4.1
Precision 5860 Tower - update to 2.4.1
Precision 7960 XL Rack - update to 2.4.4
Precision 7960 Rack - update to 2.4.4
HPE ProLiant DL320 Gen11 Server - update to 2.30_08-09-2024
HPE StoreEasy 1570 Performance - update to 2.30_08-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380a Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL560 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML110 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.30_08-09-2024
HPE Compute Edge Server e930t - update to 2.30_08-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.30_08-09-2024
HPE StoreEasy 1470 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1470 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1570 Storage - update to 2.30_08-09-2024
HPE ProLiant DL110 Gen11 - update to 2.30_08-09-2024
HPE Alletra 4140 - update to 2.30_08-09-2024
HPE Alletra 4120 - update to 2.30_08-09-2024
HPE Alletra 4110 - update to 2.30_08-09-2024
HPE StoreEasy 1670 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1670 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Performance Storage - update to 2.30_08-09-2024
Apstra - update to 6.0.0
HPE SimpliVity 380 Gen11 - update to 2024_1129
microcode_ctl - update to 20241112-1
ucode-intel - addressed in versions 20241112-146.1, 20241112-150200.50.1
ucode-intel-debugsource - update to 20241112-146.1
ucode-intel-debuginfo - update to 20241112-146.1
microcode_ctl - addressed in versions 2.1-58.5.fc39, 2.1-61.5.fc40, 2.1-67.fc41
Precision 7960 Tower - update to 2.4.1
Precision 5860 Tower - update to 2.4.1
Precision 7960 XL Rack - update to 2.4.4
Precision 7960 Rack - update to 2.4.4
HPE ProLiant DL320 Gen11 Server - update to 2.30_08-09-2024
HPE StoreEasy 1570 Performance - update to 2.30_08-09-2024
HPE ProLiant DL360 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380 Gen11 Server - update to 2.30_08-09-2024
HPE ProLiant DL380a Gen11 - update to 2.30_08-09-2024
HPE ProLiant DL560 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML110 Gen11 - update to 2.30_08-09-2024
HPE ProLiant ML350 Gen11 Server - update to 2.30_08-09-2024
HPE Compute Edge Server e930t - update to 2.30_08-09-2024
HPE Synergy 480 Gen11 Compute Module - update to 2.30_08-09-2024
HPE StoreEasy 1470 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1470 Performance - update to 2.30_08-09-2024
HPE StoreEasy 1570 Storage - update to 2.30_08-09-2024
HPE ProLiant DL110 Gen11 - update to 2.30_08-09-2024
HPE Alletra 4140 - update to 2.30_08-09-2024
HPE Alletra 4120 - update to 2.30_08-09-2024
HPE Alletra 4110 - update to 2.30_08-09-2024
HPE StoreEasy 1670 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1670 Performance Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Storage - update to 2.30_08-09-2024
HPE StoreEasy 1870 Performance Storage - update to 2.30_08-09-2024
Apstra - update to 6.0.0
HPE SimpliVity 380 Gen11 - update to 2024_1129
microcode_ctl - update to 20241112-1
ucode-intel - addressed in versions 20241112-146.1, 20241112-150200.50.1
ucode-intel-debugsource - update to 20241112-146.1
ucode-intel-debuginfo - update to 20241112-146.1
External References
Related Security Bulletins
- Two privilege escalation vulnerabilities in Intel Xeon processors with Intel SGX
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Ubuntu update for intel-microcode
- Fedora 39 update for microcode_ctl
- Fedora 40 update for microcode_ctl
- Fedora 41 update for microcode_ctl
- openEuler update for microcode_ctl
- Multiple vulnerabilities in Dell Precision Rack BIOS
- Multiple vulnerabilities in Dell Client Platform for Intel Xeon Processor with Intel SGX and UPLR2
- Multiple vulnerabilities in HPE SimpliVity 380 Gen11
- Multiple vulnerabilities in Certain HPE ProLiant DL/ML, Alletra, Synergy, and Edgeline Servers Using Certain Intel Processors
- Multiple vulnerabilities in Certain HPE StoreEasy Servers Using Certain Intel Processors
- Juniper Apstra update for Intel-microcode package