Database/Firmware, BMC & network fabric
Intel processors supporting SGX (memory protection): Insufficient memory protection on SGX-capable processors gives
CVSS 7.8CVE-2019-0123Firmware, BMC & network fabriccurated
Impact
Insufficient memory protection on SGX-capable processors gives a privileged local user a privilege-escalation path. Practically, another entry on the list of reasons an SGX platform needs both microcode currency and enforced re-attestation.
Who can reach it
Privileged local access on the host.
What to do
Microcode update and TCB recovery. Late-loadable microcode where the OS ships it; reboot required.
References
Related entries
- Intel processor graphics blitter command streamer: The graphics blitter accepted commands that could reference memoryCVE-2019-0155 · Intel processor graphics blitter command streamerHigh
- Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leakCVE-2019-14565 · Intel SGX SDKHigh
- Intel SGX SDK: Insufficient input validation in the SGX SDK's generated edge routines, letting a local userCVE-2019-14566 · Intel SGX SDKHigh
- Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilegeCVE-2020-0561 · Intel SGX SDK (< 2.6.100.1)High
- AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphicsCVE-2020-12929 · AMD PSP trusted applications shipped in the AMD Graphics DriverHigh
- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedCVE-2020-12930 · AMD Secure Processor (ASP) driversHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.