Information disclosure in Intel SGX SDK for Windows and Intel SGX SDK for Linux - CVE-2020-0551

 

Information disclosure in Intel SGX SDK for Windows and Intel SGX SDK for Linux - CVE-2020-0551

Published: March 10, 2020


Vulnerability identifier: #VU25898
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0551
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.


Affected software

Intel SGX SDK for Windows
Intel SGX SDK for Linux
Xen
openEuler
binutils
binutils-debuginfo
binutils-debugsource
binutils-help
binutils-devel

How to mitigate CVE-2020-0551

Install updates from vendor's website.

The list of affected processor families is available here:

https://software.intel.com/security-software-guidance/processors-affected-transient-execution-attack-mitigation-product-cpu-model



Intel SGX SDK for Linux - update to 2.9.100.2
binutils - update to 2.34-9
binutils-debuginfo - update to 2.34-9
binutils-debugsource - update to 2.34-9
binutils-help - update to 2.34-9
binutils-devel - update to 2.34-9

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins