First published: Tue Mar 12 2019(Updated: )
Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Software Guard Extensions | <2.1 | |
Microsoft Windows | ||
Intel Software Guard Extensions | <2.2 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0122 has a high severity rating due to the potential for information disclosure and denial of service.
To mitigate CVE-2019-0122, upgrade to Intel SGX SDK for Linux version 2.2 or newer and Intel SGX SDK for Windows version 2.1 or newer.
CVE-2019-0122 affects users of Intel SGX SDK for both Linux and Windows prior to the specified versions.
CVE-2019-0122 is classified as a double free vulnerability which can lead to local escalation of privileges.
CVE-2019-0122 requires local access for exploitation, thus it cannot be exploited remotely.