CVE-2022-27499: Medium severity intel sgx sdk for windows vulnerability
Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-27499?
CVE-2022-27499 refers to a vulnerability in the Intel(R) SGX SDK software that allows a privileged user to potentially enable information disclosure via local access.
What is the severity of CVE-2022-27499?
The severity of CVE-2022-27499 is medium with a score of 4.4.
Which software versions are affected by CVE-2022-27499?
CVE-2022-27499 affects Intel Sgx Sdk versions up to but not including 2.17.100.1 for Windows and up to but not including 2.18.100.1 for Linux.
How can CVE-2022-27499 be exploited?
CVE-2022-27499 can be exploited by a privileged user through a premature release of a resource during the expected lifetime.
Is there a fix for CVE-2022-27499?
To mitigate CVE-2022-27499, users should update their Intel(R) SGX SDK software to a version higher than 2.17.100.1 for Windows or 2.18.100.1 for Linux.