Privilege escalation in Intel products - CVE-2018-18098
Published: January 15, 2019
Vulnerability identifier: #VU16991
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-18098
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges.
The weakness exists due to improper file verification in install routine. A local attacker can supply a specially crafted and gain elevated privileges to conduct further attacks.
The weakness exists due to improper file verification in install routine. A local attacker can supply a specially crafted and gain elevated privileges to conduct further attacks.
Affected software
Intel SGX Platform Software for Linux
Intel SGX Platform Software for Windows
Intel SGX SDK for Linux
Intel SGX SDK for Windows
Intel SGX Platform Software for Windows
Intel SGX SDK for Linux
Intel SGX SDK for Windows
How to mitigate CVE-2018-18098
Update Intel SGX for Windows to version 2.2.100.
Update Intel SGX for Linux to version 2.4.100.
Update Intel SGX for Linux to version 2.4.100.
Intel SGX Platform Software for Linux - update to 2.4.100
Intel SGX Platform Software for Windows - update to 2.2.100
Intel SGX SDK for Linux - update to 2.4.100
Intel SGX SDK for Windows - update to 2.2.100
Intel SGX Platform Software for Windows - update to 2.2.100
Intel SGX SDK for Linux - update to 2.4.100
Intel SGX SDK for Windows - update to 2.2.100