CVE-2023-45745: Input Validation
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.18.04.1+ - Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.20.04.1 - Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.24.04.1 - Upgrade
Upgrade
ubuntu/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.0ubuntu0.16.04.1+ - Upgrade
Upgrade
debian/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240514.1~deb11u1Fixed in 3.20240514.1~deb12u1Fixed in 3.20240813.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.5.05.46.698
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45745?
CVE-2023-45745 is classified as a vulnerability that may allow escalation of privileges by a privileged user.
How do I fix CVE-2023-45745?
To fix CVE-2023-45745, upgrade the affected Intel microcode to the recommended version specific to your operating system.
Which versions of Intel microcode are affected by CVE-2023-45745?
Versions of Intel microcode before 1.5.05.46.698 are affected by CVE-2023-45745.
What type of systems are impacted by CVE-2023-45745?
CVE-2023-45745 impacts systems running specific versions of Intel microcode on Ubuntu and Debian distributions.
Is local access required to exploit CVE-2023-45745?
Yes, local access is required to exploit CVE-2023-45745.