Permissions, Privileges, and Access Controls in Intel products - CVE-2020-24516

 

Permissions, Privileges, and Access Controls in Intel products - CVE-2020-24516

Published: June 17, 2021


Vulnerability identifier: #VU54197
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24516
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to escalate privileges on the system.

The vulnerability exists due to modification of assumed-immutable data in subsystem, which leads to security restrictions bypass and privilege escalation.


Affected software

Intel C240 Series Chipset
Intel Atom Processor P5000 Series
3rd Generation Intel Xeon Scalable Processors
Intel C620A Series Chipset
7th Generation Intel Core Processors
Intel 100 Series Chipset
8th Generation Intel Core Processors
Intel 200 Series Chipset
Intel X299 Chipset
Intel C420 Chipset
Intel C620 Series Chipset
Intel Celeron Processor 4000 Series
Intel 300 Series Chipset
Converged Security and Management Engine (CSME)
10th Generation Intel Core Processors
Intel Core i3 L13G4
Intel Core i5 L16G7
Intel Celeron Processor N Series
Intel Pentium Processor Silver Series
Intel Celeron Processor G Series
Intel Xeon W Processor 1200
Intel Xeon W Processor 10000
Intel 400 Series Chipset
Intel Pentium Gold Processor Series
Intel Celeron Processor 6000 Series
11th Generation Intel Core Processors
Intel Server Platform Services Firmware

How to mitigate CVE-2020-24516

Install updates from vendor's website.

Intel C240 Series Chipset - addressed in versions SPS_E3_05.01.04.300.0, 12.0.81
Intel Server Platform Services Firmware - addressed in versions SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
Intel Atom Processor P5000 Series - update to SPS_SoC-A_05.00.03.091.0
3rd Generation Intel Xeon Scalable Processors - addressed in versions SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
Intel C620A Series Chipset - addressed in versions SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
7th Generation Intel Core Processors - update to 11.8.86
Intel 100 Series Chipset - update to 11.8.86
8th Generation Intel Core Processors - update to 11.8.86
Intel 200 Series Chipset - update to 11.8.86
Intel X299 Chipset - update to 11.12.86
Intel C420 Chipset - update to 11.12.86
Intel C620 Series Chipset - update to 11.22.86
Intel Celeron Processor 4000 Series - update to 12.0.81
Intel 300 Series Chipset - update to 12.0.81
Converged Security and Management Engine (CSME) - addressed in versions 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22
10th Generation Intel Core Processors - update to 13.0.47
Intel Core i3 L13G4 - update to 13.30.17
Intel Core i5 L16G7 - update to 13.30.17
Intel Celeron Processor N Series - update to 13.50.11
Intel Pentium Processor Silver Series - update to 13.50.11
Intel Celeron Processor G Series - update to 14.1.53
Intel Xeon W Processor 1200 - update to 14.1.53
Intel Xeon W Processor 10000 - update to 14.1.53
Intel 400 Series Chipset - update to 14.1.53
Intel Pentium Gold Processor Series - update to 14.5.32
Intel Celeron Processor 6000 Series - update to 15.0.22
11th Generation Intel Core Processors - update to 15.0.22

External References

Related Security Bulletins