First published: Fri Nov 11 2022(Updated: )
Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Sgx Sdk | <2.17.100.1 | |
Intel Sgx Sdk | <2.18.100.1 | |
Intel sgx sdk windows | <2.17.100.1 | |
Intel sgx sdk linux | <2.18.100.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27499 refers to a vulnerability in the Intel(R) SGX SDK software that allows a privileged user to potentially enable information disclosure via local access.
The severity of CVE-2022-27499 is medium with a score of 4.4.
CVE-2022-27499 affects Intel Sgx Sdk versions up to but not including 2.17.100.1 for Windows and up to but not including 2.18.100.1 for Linux.
CVE-2022-27499 can be exploited by a privileged user through a premature release of a resource during the expected lifetime.
To mitigate CVE-2022-27499, users should update their Intel(R) SGX SDK software to a version higher than 2.17.100.1 for Windows or 2.18.100.1 for Linux.