Improper isolation or compartmentalization in Intel products - CVE-2023-49141

 

Improper isolation or compartmentalization in Intel products - CVE-2023-49141

Published: August 20, 2024


Vulnerability identifier: #VU96240
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49141
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an improper isolation in some Intel Processors stream cache mechanism. A local user can execute arbitrary code with elevated privileges.


Affected software

4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
Intel Xeon Scalable Processors with Intel vRAN
Intel Xeon Processor E Family
12th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processors
13th Generation Intel Core Processors
4th Generation Intel Xeon Edge Enhanced Processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
13th Generation Intel Core i7 processors
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance

How to mitigate CVE-2023-49141

Install updates from vendor's website.

RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
microcode_ctl - update to 2.1-47.43
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1

External References

Related Security Bulletins