CVE-2022-40974: Medium severity intel integrated performance primitives vulnerability
Published May 10, 2023
·Updated
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
1 affected component
Intel Integrated Performance Primitives Cryptography<2021.6
Event History
May 10, 2023
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-40974?
CVE-2022-40974 is a vulnerability in the Intel(R) IPP Cryptography software that may allow a privileged user to potentially enable information disclosure via local access.
2
What is the severity of CVE-2022-40974?
The severity of CVE-2022-40974 is classified as medium.
3
How does CVE-2022-40974 affect the Intel Integrated Performance Primitives Cryptography software?
CVE-2022-40974 affects the Intel Integrated Performance Primitives Cryptography software versions prior to 2021.6.
4
How can a privileged user potentially enable information disclosure using CVE-2022-40974?
A privileged user can potentially enable information disclosure through local access using CVE-2022-40974.
5
Is there a patch available to fix CVE-2022-40974?
Yes, upgrading to Intel Integrated Performance Primitives Cryptography software version 2021.6 or later can fix CVE-2022-40974.