#VU54191 Incomplete cleanup in Intel products - CVE-2020-24489

 

#VU54191 Incomplete cleanup in Intel products - CVE-2020-24489

Published: June 17, 2021 / Updated: June 21, 2021


Vulnerability identifier: #VU54191
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-24489
CWE-ID: CWE-459
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
10th Generation Intel Core Processors
11th Generation Intel Core Processors
Intel Pentium Processor N Series Intel Celeron Processor J Series
Intel Celeron Processor N Series Intel Atom Processor
Intel Celeron Processor N Series
Intel Pentium Processor Silver Series
Intel Core Processors with Intel Hybrid Technology
Intel Pentium Processor J Series
Intel Atom Processor E3900 Series
Intel Pentium Processor N Series
Software vendor:
Intel

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incomplete cleanup, which leads to security restrictions bypass and privilege escalation.


Remediation

Install updates from vendor's website.

External links