A potential security vulnerability in some Intel® Software Guard Extensions (SGX) Data Center Attestation Primitives (DCAP) software may allow information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.
CVEID: CVE-2023-42776
Description: Improper input validation in some Intel® SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially enable information disclosure via local access.
CVSS Base Score: 3.8 Low
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Intel® SGX DCAP software for Windows before version 1.19.100.3.
Intel recommends updating Intel® SGX DCAP software for Windows to version 1.19.100.3 or later.
Updates are available for download at this location:
<https://www.intel.com/content/www/us/en/download/683952/intel-software-guard-extensions-intel-sgx-driver-and-data-center-attestation-primitives-intel-sgx-dcap.html>
Intel would like to thank Jo Van Bulck, DistriNet, KU Leuven, Belgium; Fritz Alder, DistriNet, KU Leuven, Belgium; Lesly-Ann Daniel, DistriNet, KU Leuven, Belgium; Frank Piessens, DistriNet, KU Leuven, Belgium; David Oswald, University of Birmingham for reporting this issue.
Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.