Impact
An omission in the handling of security‑relevant information within Intel R Software Guard Extensions (SGX) Data Center Attestation Primitives can allow a kernel to perform an action that may result in denial of service or data alteration. The flaw is formally identified as CWE‑223 (Incorrect Token Validation) and, according to the description, can lead to integrity impact rated as high while availability impact remains low and confidentiality is unaffected. The CVSS score of 4.3 indicates a low overall severity, yet the potential to modify data with elevated privileges makes the issue relevant for environments where integrity is critical.
Affected Systems
Intel R Software Guard Extensions Data Center Attestation Primitives are the affected products. No version information is disclosed in the advisory, so all builds using this component are potentially impacted.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is unlikely at present. However, the attack requires a privileged user and a high‑complexity local attack with no user interaction. If such conditions are met, an attacker could cause system instability or alter sensitive data. The low CVSS score and minimal exploitation probability reduce the urgency, but the potential integrity impact warrants careful monitoring.
OpenCVE Enrichment