Information disclosure in Intel Integrated Performance Primitives - CVE-2018-12155
Published: December 7, 2018 / Updated: December 7, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to data leakage that may occur in certain cryptographic libraries used by the affected software. A local attacker can access sensitive information that can be used to conduct further attacks.
Affected software
Intel SGX Platform Software for Linux
Intel SGX Platform Software for Windows
Intel SGX SDK for Linux
Intel SGX SDK for Windows
How to mitigate CVE-2018-12155
Intel SGX Platform Software for Linux - update to 2.4.100
Intel SGX Platform Software for Windows - update to 2.2.100
Intel SGX SDK for Linux - update to 2.4.100
Intel SGX SDK for Windows - update to 2.2.100