Improper access control in Intel products - CVE-2023-32666

 

Improper access control in Intel products - CVE-2023-32666

Published: March 13, 2024


Vulnerability identifier: #VU87486
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32666
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions within the on-chip debug and test interface when using Intel SGX or Intel TDX. A local privileged user can bypass implemented security restrictions and escalate privileges on the system.


Affected software

4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2023-32666

Install updates from vendor's website.

PowerFlex Appliance - update to IC-46.380.01
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39

External References

Related Security Bulletins