CVE-2019-14566: Input Validation
Published Nov 14, 2019
·Updated
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
Affected Software
10 affected components
Intel Software Guard Extensions Sdk=2.3.100.49777
Intel Software Guard Extensions Sdk=2.3.101.50222
Intel Software Guard Extensions Sdk=2.4.100.51291
Microsoft Windows
Intel Software Guard Extensions Sdk=2.2.100.45311
Intel Software Guard Extensions Sdk=2.3.100.46354
Intel Software Guard Extensions Sdk=2.4.100.48163
Intel Software Guard Extensions Sdk=2.5.100.49891
Intel Software Guard Extensions Sdk=2.6.100.51363
Linux Linux kernel
Event History
Nov 14, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-14566?
CVE-2019-14566 is a vulnerability in Intel SGX SDK that allows an authenticated user to enable information disclosure, escalation of privilege, or denial of service via local access.
2
Which software versions are affected by CVE-2019-14566?
CVE-2019-14566 affects Intel SGX SDK versions 2.3.100.49777, 2.3.101.50222, and 2.4.100.51291.
3
Is Microsoft Windows vulnerable to CVE-2019-14566?
No, Microsoft Windows is not vulnerable to CVE-2019-14566.
4
What is the severity of CVE-2019-14566?
CVE-2019-14566 has a severity score of 7.8 (high).
5
How can I fix CVE-2019-14566?
To fix CVE-2019-14566, update your Intel SGX SDK to a non-vulnerable version as specified in the advisory from Intel.