PT-2019-5580 · Intel · Intel Processors
CVE-2019-14607
·
Publicado
2019-12-11
·
Atualizado
2023-02-02
CVSS v3.1
5.3
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Intel Processors (affected versions not specified)
Description
The issue is related to insufficient checking of exceptional states in Intel processor microcode, potentially allowing an authenticated user to partially escalate privileges, cause a denial of service, and/or disclose information via local access. This vulnerability can be exploited through manipulation of the dynamic voltage and frequency scaling mechanism in the CPU, potentially damaging data cell contents, including those used in Intel SGX isolated enclaves. The attack, known as Plundervolt, may enable a local user to gain elevated privileges, cause a service disruption, and access protected data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Check for Exceptional Conditions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Intel Processors