Improper isolation or compartmentalization in Intel products - CVE-2023-49141

 

Improper isolation or compartmentalization in Intel products - CVE-2023-49141

Published: August 20, 2024


Vulnerability identifier: #VU96240
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-49141
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Intel
Affected software:
4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
Intel Xeon CPU Max Series processors (High Bandwidth Memory HBM)
Intel Xeon Scalable Processors with Intel vRAN
Intel Xeon Processor E Family
12th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processors
13th Generation Intel Core Processors
4th Generation Intel Xeon Edge Enhanced Processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
13th Generation Intel Core i7 processors

Detailed vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an improper isolation in some Intel Processors stream cache mechanism. A local user can execute arbitrary code with elevated privileges.


How to mitigate CVE-2023-49141

Install updates from vendor's website.

Sources