CVE-2024-39283: High severity Intel TDX module vulnerability
Incomplete filtering of special elements in Intel(R) TDX module software before version TDX1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intel(R) TDX module softwareto a version that resolves this vulnerability.Fixed in TDX_1.5.01.00.592
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39283?
The severity of CVE-2024-39283 is considered to be high due to the potential for privilege escalation.
How do I fix CVE-2024-39283?
To fix CVE-2024-39283, upgrade to the latest version of Intel TDX module software, specifically version TDX_1.5.01.00.593 or later.
What type of vulnerability is CVE-2024-39283?
CVE-2024-39283 is classified as a privilege escalation vulnerability affecting Intel TDX module software.
Who is affected by CVE-2024-39283?
CVE-2024-39283 affects users of Intel TDX module software versions prior to 1.5.01.00.592.
Can an unauthenticated user exploit CVE-2024-39283?
No, an authenticated user is required to exploit CVE-2024-39283.