CVE-2024-21820: High severity debian/intel-microcode vulnerability
Published Nov 13, 2024
·Updated
Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
1 affected componentFixes available
debian/intel-microcode<=3.20240813.1~deb11u1, <=3.20240910.1~deb11u1, <=3.20240910.1~deb12u1, <=3.20231114.1~deb12u1
3.20241112.1
Event History
Nov 13, 2024
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Dec 11, 2024
Data Sourced
via Ubuntu·03:11 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21820?
The severity of CVE-2024-21820 is not explicitly rated but it may lead to potential privilege escalation for a local user.
2
How do I fix CVE-2024-21820?
To fix CVE-2024-21820, update to the Intel microcode version 3.20241112.1 or later.
3
Which systems are affected by CVE-2024-21820?
CVE-2024-21820 affects configurations of Intel Xeon processors utilizing Intel SGX.
4
Who can exploit CVE-2024-21820?
CVE-2024-21820 can potentially be exploited by a privileged user with local access to the affected systems.
5
What configurations are vulnerable in CVE-2024-21820?
CVE-2024-21820 involves incorrect default permissions in specific configurations of Intel Xeon processor memory controllers.