#VU64376 Incomplete cleanup in Intel products - CVE-2022-21127
Published: June 14, 2022 / Updated: July 20, 2022
Vulnerability identifier: #VU64376
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-21127
CWE-ID: CWE-459
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Intel SGX PSW for Windows
Intel SGX DCAP for Windows
Intel SGX PSW for Linux
Intel SGX DCAP for Linux
Intel SGX SDK for Windows
Intel SGX SDK for Linux
Intel SGX PSW for Windows
Intel SGX DCAP for Windows
Intel SGX PSW for Linux
Intel SGX DCAP for Linux
Intel SGX SDK for Windows
Intel SGX SDK for Linux
Software vendor:
Intel
Intel
Description
The vulnerability allows a local user to gain access to sensitive information on the system.
The vulnerability exists due to incomplete cleanup in specific special register read operations. A local user can enable information disclosure.
Remediation
Install updates from vendor's website.