CVE-2019-0122

HIGH

Intel SGX SDK < 2.1 - Authenticated Double Free via Local Access

Title source: llm
STIX 2.1

Description

Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0005
EPSS Percentile 17.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-415
Status published
Products (1)
intel/software_guard_extensions_sdk < 2.1
Published Mar 14, 2019
Tracked Since Feb 18, 2026