Improper isolation or compartmentalization in Intel products - CVE-2023-49141
Published: August 20, 2024
Vulnerability identifier: #VU96240
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49141
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an improper isolation in some Intel Processors stream cache mechanism. A local user can execute arbitrary code with elevated privileges.
Affected software
4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
Intel Xeon Scalable Processors with Intel vRAN
Intel Xeon Processor E Family
12th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processors
13th Generation Intel Core Processors
4th Generation Intel Xeon Edge Enhanced Processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
13th Generation Intel Core i7 processors
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
Intel Xeon Scalable Processors with Intel vRAN
Intel Xeon Processor E Family
12th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processors
13th Generation Intel Core Processors
4th Generation Intel Xeon Edge Enhanced Processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
13th Generation Intel Core i7 processors
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance
How to mitigate CVE-2023-49141
Install updates from vendor's website.
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
microcode_ctl - update to 2.1-47.43
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
microcode_ctl - update to 2.1-47.43
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1
External References
Related Security Bulletins
- Privilege escalation in Intel Processor Stream Cache
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- openEuler update for microcode_ctl
- Amazon Linux AMI update for microcode_ctl
- Dell RecoverPoint for Virtual Machines update for third-party components
- Dell CloudBoost Virtual Appliance update for third-party components