Incomplete cleanup in Intel products - CVE-2022-21127
Published: June 14, 2022 / Updated: July 20, 2022
Vulnerability identifier: #VU64376
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-21127
CWE-ID: CWE-459
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Intel
Affected software:
Intel SGX PSW for Windows
Intel SGX DCAP for Windows
Intel SGX PSW for Linux
Intel SGX DCAP for Linux
Intel SGX SDK for Windows
Intel SGX SDK for Linux
Intel SGX PSW for Windows
Intel SGX DCAP for Windows
Intel SGX PSW for Linux
Intel SGX DCAP for Linux
Intel SGX SDK for Windows
Intel SGX SDK for Linux
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information on the system.
The vulnerability exists due to incomplete cleanup in specific special register read operations. A local user can enable information disclosure.
How to mitigate CVE-2022-21127
Install updates from vendor's website.