Incorrect behavior order in Intel products - CVE-2024-24853

 

Incorrect behavior order in Intel products - CVE-2024-24853

Published: August 20, 2024


Vulnerability identifier: #VU96259
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24853
CWE-ID: CWE-696
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an incorrect behavior order in SMI Transfer monitor (STM). A local user can escalate privileges on the system.


Affected software

2nd generation Intel Core processors
2nd Generation Intel Xeon Scalable Processors
Intel Xeon W-1300 Processor Family
Intel Xeon E-2300 processor family
Intel Celeron Processor G Series
Intel Pentium Processors
Intel Celeron Processor 5000 Series
Intel Pentium Gold Processor Series
7th Generation Intel Core Processors
4th Generation Intel Core Processor Family
3rd Generation Intel Core Processors
8th Generation Intel Core Processors
Intel Xeon Processors
11th Generation Intel Core Processors
10th Generation Intel Core Processors
Intel Xeon D Processors
6th Generation Intel Core Processors
Intel Xeon E Processors
3rd Generation Intel Xeon Scalable Processors
Intel Core X-series Processor
Intel Xeon W Processors
Intel Processor Microcode Package for Linux
Superdome Flex 280 Server
HPE Edgeline e920 Server Blade
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL220n Gen10 Plus Server
HPE ProLiant XL290n Gen10 Plus Server
HPE ProLiant DL360 Gen10 Plus server
HPE Edgeline e920d Server Blade
HPE Edgeline e920t Server Blade
HPE ProLiant DX360 Gen10 Plus server
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
HPE ProLiant MicroServer Gen10 Plus v2
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX220n Gen10 Plus server
Precision 7920 XL Rack
HPE ProLiant DX170r Gen10 server
HPE ProLiant DX360 Gen10 server
HPE ProLiant DX190r Gen10 server
HPE ProLiant DX380 Gen10 server
HPE ProLiant DX560 Gen10 server
HPE ProLiant DX4200 Gen10 server
HPE ProLiant DL20 Gen10 Server
HPE ProLiant ML30 Gen10 Server
HPE ProLiant MicroServer Gen10 Plus
HPE ProLiant m750 Server Blade
HPE ProLiant ML30 Gen10 Plus server
Superdome Flex Server
HPE SimpliVity 380 Gen10
HPE SimpliVity 380 Gen10 G
HPE SimpliVity 380 Gen10 H
HPE SimpliVity 190r Gen10 Server
HPE SimpliVity 170r Gen10 Server
HPE SimpliVity 380 Gen10 Plus
9th Generation Intel Core Processors
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel-debugsource
ucode-intel-debuginfo
ucode-intel
HPE Synergy 480 Gen10 Plus Compute Module
CloudBoost Virtual Appliance
Precision 7920

How to mitigate CVE-2024-24853

Install updates from vendor's website.

Intel Processor Microcode Package for Linux - update to 20240813
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
Superdome Flex 280 Server - update to 1.90.12
microcode_ctl - update to 2.1-47.44
microcode_ctl - addressed in versions 2.1-58.2.fc39, 2.1-61.2.fc40, 2.1-64.fc41
HPE Edgeline e920 Server Blade - update to 2.20_08-07-2024
HPE Apollo 4200 Gen10 Plus System - update to 2.20_08-07-2024
HPE ProLiant XL220n Gen10 Plus Server - update to 2.20_08-07-2024
HPE ProLiant XL290n Gen10 Plus Server - update to 2.20_08-07-2024
HPE Synergy 480 Gen10 Plus Compute Module - update to 2.20_08-07-2024
HPE ProLiant DL360 Gen10 Plus server - update to 2.20_08-07-2024
HPE Edgeline e920d Server Blade - update to 2.20_08-07-2024
HPE Edgeline e920t Server Blade - update to 2.20_08-07-2024
HPE ProLiant DX360 Gen10 Plus server - update to 2.20_08-07-2024
HPE StoreEasy 1860 Storage - update to 2.20_08-07-2024
HPE StoreEasy 1660 Storage - update to 2.20_08-07-2024
HPE ProLiant MicroServer Gen10 Plus v2 - update to 2.20_08-07-2024
HPE ProLiant DL380 Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DL110 Gen10 Plus Telco server - update to 2.20_08-07-2024
HPE ProLiant DL20 Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DX380 Gen10 Plus server - update to 2.20_08-07-2024
HPE ProLiant DX220n Gen10 Plus server - update to 2.20_08-07-2024
Precision 7920 XL Rack - update to 2.22.1
Precision 7920 - update to 2.22.1
HPE ProLiant DX170r Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DX360 Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DX190r Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DX380 Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DX560 Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DX4200 Gen10 server - update to 3.30_07-31-2024
HPE ProLiant DL20 Gen10 Server - update to 3.40_08-01-2024
HPE ProLiant ML30 Gen10 Server - update to 3.40_08-01-2024
HPE ProLiant MicroServer Gen10 Plus - update to 3.40_08-01-2024
HPE ProLiant m750 Server Blade - update to 3.40_08-01-2024
HPE ProLiant ML30 Gen10 Plus server - update to 3.40_08-01-2024
Superdome Flex Server - update to 4.0.10
CloudBoost Virtual Appliance - update to 19.12.0.1
HPE SimpliVity 380 Gen10 - update to 2024_1129
HPE SimpliVity 380 Gen10 G - update to 2024_1129
HPE SimpliVity 380 Gen10 H - update to 2024_1129
HPE SimpliVity 190r Gen10 Server - update to 2024_1129
HPE SimpliVity 170r Gen10 Server - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
microcode_ctl - update to 20240813-1
ucode-intel-debugsource - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel - update to 20240813-140.1

External References

Related Security Bulletins