Improper isolation or compartmentalization in Intel products - CVE-2021-0060
Published: February 9, 2022 / Updated: July 24, 2022
Vulnerability identifier: #VU60450
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0060
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to insufficient compartmentalization in HECI subsystem for the Intel(R) SPS. An attacker with physical access to the system can execute arbitrary code with elevated privileges.
Affected software
Intel C624D chipset
Intel C600 Series Chipset
Intel Xeon Processor D 1500
Intel C610 Series Chipset
Intel C240 Series Chipset
Intel Xeon D Processor 2000 Series
Intel Atom Processor P5000 Series
Intel C620 Series Chipset
Intel C620A Series Chipset
Intel Xeon W Processor 1300 Series
11th Generation Intel Core Processors
Intel Celeron Processor 6000 Series
Intel Pentium Gold Processor Series
VEP4600-16 Core
VEP4600-4 Core
VEP4600-8 Core
EMC Integrated Data Protection Appliance
S5212F-ON
S5224F-ON
S5232F-ON
S5248F-ON
Z9264F-ON
N3200-ON
N2200-ON
VEP1425
VEP1445
VEP1485
Z9432F-ON
S5448F-ON
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
Intel C600 Series Chipset
Intel Xeon Processor D 1500
Intel C610 Series Chipset
Intel C240 Series Chipset
Intel Xeon D Processor 2000 Series
Intel Atom Processor P5000 Series
Intel C620 Series Chipset
Intel C620A Series Chipset
Intel Xeon W Processor 1300 Series
11th Generation Intel Core Processors
Intel Celeron Processor 6000 Series
Intel Pentium Gold Processor Series
VEP4600-16 Core
VEP4600-4 Core
VEP4600-8 Core
EMC Integrated Data Protection Appliance
S5212F-ON
S5224F-ON
S5232F-ON
S5248F-ON
Z9264F-ON
N3200-ON
N2200-ON
VEP1425
VEP1445
VEP1485
Z9432F-ON
S5448F-ON
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub
How to mitigate CVE-2021-0060
Install updates from vendor's website.
Intel C624D chipset - update to ADAS_ME_ANL_01.00.05.004.0
Intel C600 Series Chipset - update to SPS_02.04.00.101.0
Intel Xeon Processor D 1500 - update to SPS_SoC-X_03.00.03.117.0
Intel C610 Series Chipset - addressed in versions SPS_PHI_03.01.03.078.0, SPS_E5_03.01.03.116.0
Intel C240 Series Chipset - update to SPS_E3_05.01.04.309.0
Intel Xeon D Processor 2000 Series - update to SPS_SoC-X_04.00.04.326.0
Intel Atom Processor P5000 Series - update to SPS_SoC-A_05.00.03.114.0
Intel C620 Series Chipset - addressed in versions SPS_E5_04.01.04.516.0, 11.22.90
Intel C620A Series Chipset - addressed in versions SPS_E5_04.04.03.281.0, SPS_E5_04.04.04.033.0
Intel Xeon W Processor 1300 Series - update to 15.0.35
11th Generation Intel Core Processors - update to 15.0.35
Intel Celeron Processor 6000 Series - update to 15.0.35
Intel Pentium Gold Processor Series - update to 15.0.35
VEP4600-16 Core - update to UFW-3.8
VEP4600-4 Core - update to UFW-3.8
VEP4600-8 Core - update to UFW-3.8
S5212F-ON - update to 3.40.0.9-15
S5224F-ON - update to 3.40.0.9-15
S5232F-ON - update to 3.40.0.9-15
S5248F-ON - update to 3.40.0.9-15
Z9264F-ON - update to 3.42.0.9-18
N3200-ON - update to 3.45.0.9-8
N2200-ON - update to 3.45.0.9-11
VEP1425 - update to 3.48.0.9-18
VEP1445 - update to 3.48.0.9-18
VEP1485 - update to 3.48.0.9-18
Z9432F-ON - update to 3.51.0.D-12
S5448F-ON - update to 3.52.0.D-11
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2210
Intel C600 Series Chipset - update to SPS_02.04.00.101.0
Intel Xeon Processor D 1500 - update to SPS_SoC-X_03.00.03.117.0
Intel C610 Series Chipset - addressed in versions SPS_PHI_03.01.03.078.0, SPS_E5_03.01.03.116.0
Intel C240 Series Chipset - update to SPS_E3_05.01.04.309.0
Intel Xeon D Processor 2000 Series - update to SPS_SoC-X_04.00.04.326.0
Intel Atom Processor P5000 Series - update to SPS_SoC-A_05.00.03.114.0
Intel C620 Series Chipset - addressed in versions SPS_E5_04.01.04.516.0, 11.22.90
Intel C620A Series Chipset - addressed in versions SPS_E5_04.04.03.281.0, SPS_E5_04.04.04.033.0
Intel Xeon W Processor 1300 Series - update to 15.0.35
11th Generation Intel Core Processors - update to 15.0.35
Intel Celeron Processor 6000 Series - update to 15.0.35
Intel Pentium Gold Processor Series - update to 15.0.35
VEP4600-16 Core - update to UFW-3.8
VEP4600-4 Core - update to UFW-3.8
VEP4600-8 Core - update to UFW-3.8
S5212F-ON - update to 3.40.0.9-15
S5224F-ON - update to 3.40.0.9-15
S5232F-ON - update to 3.40.0.9-15
S5248F-ON - update to 3.40.0.9-15
Z9264F-ON - update to 3.42.0.9-18
N3200-ON - update to 3.45.0.9-8
N2200-ON - update to 3.45.0.9-11
VEP1425 - update to 3.48.0.9-18
VEP1445 - update to 3.48.0.9-18
VEP1485 - update to 3.48.0.9-18
Z9432F-ON - update to 3.51.0.D-12
S5448F-ON - update to 3.52.0.D-11
Dell EMC VxRail Appliance - update to 4.5.480
Integrated System for Microsoft Azure Stack Hub - update to 2210
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel Chipset Firmware
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub
- Multiple vulnerabilities in Dell Networking BIOS drivers
- Multiple vulnerabilities in Dell Networking Products for Intel
- Multiple vulnetabilities in Dell EMC Integrated Data Protection Appliance