CVE-2024-23918: High severity debian/intel-microcode vulnerability
Published Nov 13, 2024
·Updated
Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
1 affected componentFixes available
debian/intel-microcode<=3.20240813.1~deb11u1, <=3.20240910.1~deb11u1, <=3.20240910.1~deb12u1, <=3.20231114.1~deb12u1
3.20241112.1
Event History
Nov 13, 2024
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Dec 11, 2024
Data Sourced
via Ubuntu·03:11 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23918?
CVE-2024-23918 has been classified with a high severity level due to its potential for privilege escalation.
2
How do I fix CVE-2024-23918?
To mitigate CVE-2024-23918, update the Intel microcode to version 3.20241112.1 or later.
3
What systems are affected by CVE-2024-23918?
CVE-2024-23918 affects Intel Xeon processors using specific memory controller configurations.
4
Who is impacted by CVE-2024-23918?
Privileged users with local access to affected systems may be impacted by CVE-2024-23918.
5
What potential risks does CVE-2024-23918 pose?
CVE-2024-23918 poses a risk of privilege escalation, allowing unauthorized access to system resources.