CVE-2018-18098

HIGH

Intel Sgx Platform Software - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.

References (1)

Core 1
Core References

Scores

CVSS v3 7.3
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
intel/sgx_platform_software < 2.2.100
intel/sgx_sdk < 2.2.100
Published Jan 10, 2019
Tracked Since Feb 18, 2026