CVE-2022-27499

LOW LAB

Intel Sgx SDK < 2.17.100.1 - Information Disclosure

Title source: rule
STIX 2.1

Description

Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.

Exploits (1)

nomisec WORKING POC
by web-logs2 · poc
https://github.com/web-logs2/snapshot-demo

Scores

CVSS v3 2.5
EPSS 0.0256
EPSS Percentile 85.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull occlum/occlum:0.26.2-ubuntu18.04

Details

CWE
CWE-672
Status published
Products (2)
intel/sgx_sdk < 2.17.100.1
intel/sgx_sdk < 2.18.100.1
Published Nov 11, 2022
Tracked Since Feb 18, 2026