Protection Mechanism Failure in Intel products - CVE-2024-24980

 

Protection Mechanism Failure in Intel products - CVE-2024-24980

Published: August 19, 2024


Vulnerability identifier: #VU96214
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24980
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient implementation of security measures. A local privileged user can escalate privileges on the system.


Affected software

3rd Generation Intel Xeon Scalable Processors
Intel Xeon D Processors
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
HPE Synergy 480 Gen11 Compute Module
HPE ProLiant DL110 Gen11
HPE ProLiant DL320 Gen11 Server
HPE ProLiant DL360 Gen11 Server
HPE ProLiant DL380 Gen11 Server
HPE ProLiant DL380a Gen11
HPE ProLiant DL560 Gen11
HPE ProLiant ML110 Gen11
HPE ProLiant ML350 Gen11 Server
HPE StoreEasy 1670 Performance Storage
HPE Alletra 4110
HPE ProLiant DX360 Gen11 server
HPE StoreEasy 1870 Performance Storage
HPE Alletra 4120
HPE Alletra 4140
HPE StoreEasy 1670 Storage
HPE StoreEasy 1870 Storage
HPE ProLiant DX380 Gen11 server
HPE Edgeline e920d Server Blade
HPE ProLiant DX220n Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL220n Gen10 Plus Server
HPE ProLiant XL290n Gen10 Plus Server
HPE Edgeline e920 Server Blade
HPE Edgeline e920t Server Blade
Precision 7920 XL Rack
HPE SimpliVity 380 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel-debugsource
ucode-intel-debuginfo
ucode-intel
HPE Synergy 480 Gen10 Plus Compute Module
CloudBoost Virtual Appliance
Precision 7920

How to mitigate CVE-2024-24980

Install updates from vendor's website.

RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
microcode_ctl - update to 2.1-47.44
microcode_ctl - addressed in versions 2.1-58.2.fc39, 2.1-61.2.fc40, 2.1-64.fc41
HPE Synergy 480 Gen11 Compute Module - update to 2.20_05-27-2024
HPE ProLiant DL110 Gen11 - update to 2.20_05-27-2024
HPE ProLiant DL320 Gen11 Server - update to 2.20_05-27-2024
HPE ProLiant DL360 Gen11 Server - update to 2.20_05-27-2024
HPE ProLiant DL380 Gen11 Server - update to 2.20_05-27-2024
HPE ProLiant DL380a Gen11 - update to 2.20_05-27-2024
HPE ProLiant DL560 Gen11 - update to 2.20_05-27-2024
HPE ProLiant ML110 Gen11 - update to 2.20_05-27-2024
HPE ProLiant ML350 Gen11 Server - update to 2.20_05-27-2024
HPE StoreEasy 1670 Performance Storage - update to 2.20_05-27-2024
HPE Alletra 4110 - update to 2.20_05-27-2024
HPE ProLiant DX360 Gen11 server - update to 2.20_05-27-2024
HPE StoreEasy 1870 Performance Storage - update to 2.20_05-27-2024
HPE Alletra 4120 - update to 2.20_05-27-2024
HPE Alletra 4140 - update to 2.20_05-27-2024
HPE StoreEasy 1670 Storage - update to 2.20_05-27-2024
HPE StoreEasy 1870 Storage - update to 2.20_05-27-2024
HPE ProLiant DX380 Gen11 server - update to 2.20_05-27-2024
HPE Edgeline e920d Server Blade - update to 2.20_08-07-2024
HPE ProLiant DX220n Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DX360 Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DX380 Gen10 Plus server - update to 2.20_08-07-2024
HPE StoreEasy 1860 Storage - update to 2.20_08-07-2024
HPE StoreEasy 1660 Storage - update to 2.20_08-07-2024
HPE ProLiant DL110 Gen10 Plus Telco server - update to 2.20_08-07-2024
HPE ProLiant DL360 Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DL380 Gen10 Plus server - update to 2.20_08-07-2024
HPE Apollo 2000 Gen10 Plus System - update to 2.20_08-07-2024
HPE Apollo 4200 Gen10 Plus System - update to 2.20_08-07-2024
HPE ProLiant XL220n Gen10 Plus Server - update to 2.20_08-07-2024
HPE ProLiant XL290n Gen10 Plus Server - update to 2.20_08-07-2024
HPE Synergy 480 Gen10 Plus Compute Module - update to 2.20_08-07-2024
HPE Edgeline e920 Server Blade - update to 2.20_08-07-2024
HPE Edgeline e920t Server Blade - update to 2.20_08-07-2024
Precision 7920 XL Rack - update to 2.22.1
Precision 7920 - update to 2.22.1
CloudBoost Virtual Appliance - update to 19.12.0.1
HPE SimpliVity 380 Gen11 - update to 2024_0830
microcode_ctl - update to 20240813-1
ucode-intel-debugsource - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel - update to 20240813-140.1

External References

Related Security Bulletins