CVE-2018-18098: High severity intel software guard extensions platform software component vulnerability
Published Jan 10, 2019
·Updated
Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.
Affected Software
3 affected components
Intel Sgx Platform Software<2.2.100
Microsoft Windows
Intel SGX SDK<2.2.100
Remediation
Event History
Jan 10, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18098.
2
What is the severity of CVE-2018-18098?
The severity of CVE-2018-18098 is high with a score of 7.3.
3
What is the affected software?
The affected software is Intel SGX SDK and Platform Software for Windows before version 2.2.100.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 732.
5
Is Microsoft Windows affected by this vulnerability?
No, Microsoft Windows is not affected by this vulnerability.
6
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by gaining local access and performing an escalation of privilege.
7
Where can I find more information about this vulnerability?
You can find more information about this vulnerability [here](https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00203.html).