Lucene search

K
freebsdFreeBSD9D8E9952-5A42-11EF-A219-1C697A616631
HistoryAug 13, 2024 - 12:00 a.m.

Intel CPUs -- multiple vulnerabilities

2024-08-1300:00:00
vuxml.freebsd.org
4
intel
cpus
vulnerabilities
privilege escalation
denial of service
microcode updates
firmware updates

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS4

7.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

PASSIVE

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H

AI Score

7.6

Confidence

Low

EPSS

0

Percentile

9.5%

Intel reports:

  A potential security vulnerability in SMI Transfer monitor (STM) may
  allow escalation of privilege.  Intel has released microcode updates
  to mitigate this potential vulnerability.
 



  A potential security vulnerability in some 3rd Generation Intel Xeon
  Scalable Processors may allow denial of service.  Intel has released
  microcode updates to mitigate this potential vulnerability.
 



  A potential security vulnerability in some 3rd, 4th, and 5th
  Generation Intel Xeon Processors may allow escalation of privilege.
  Intel has released firmware updates to mitigate this potential
  vulnerability.
 



  A potential security vulnerability in the Intel Core Ultra Processor
  stream cache mechanism may allow escalation of privilege.  Intel has
  released microcode updates to mitigate this potential vulnerability.
 



  A potential security vulnerability in some Intel Processor stream
  cache mechanisms may allow escalation of privilege.  Intel has
  released microcode updates to mitigate this potential vulnerability.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchcpu-microcode-intel< 20240813UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS4

7.3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

PASSIVE

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H

AI Score

7.6

Confidence

Low

EPSS

0

Percentile

9.5%