CVE-2019-1370HighCVSS 7.0

Open Enclave SDK Information Disclosure Vulnerability

Published
November 12, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information stored in the Enclave. To exploit this vulnerability, an attacker would have to successfully compromise the host application running the enclave. The attacker can then pivot to the enclave and exploit this vulnerability without user interaction. The security update addresses the vulnerability by modifying how Open Enclave SDK handle objects in memory.

🎯 Affected products1

  • Open Enclave SDK

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)