Information disclosure in Intel Integrated Performance Primitives - CVE-2018-12155

 

Information disclosure in Intel Integrated Performance Primitives - CVE-2018-12155

Published: December 7, 2018 / Updated: December 7, 2018


Vulnerability identifier: #VU16332
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12155
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to data leakage that may occur in certain cryptographic libraries used by the affected software. A local attacker can access sensitive information that can be used to conduct further attacks.


Affected software

Intel Integrated Performance Primitives
Intel SGX Platform Software for Linux
Intel SGX Platform Software for Windows
Intel SGX SDK for Linux
Intel SGX SDK for Windows

How to mitigate CVE-2018-12155

Update to version 2019 Update 1.

Intel Integrated Performance Primitives - update to 2019 update1
Intel SGX Platform Software for Linux - update to 2.4.100
Intel SGX Platform Software for Windows - update to 2.2.100
Intel SGX SDK for Linux - update to 2.4.100
Intel SGX SDK for Windows - update to 2.2.100

External References

Related Security Bulletins