SB2022052312 - Security restrictions bypass in Intel Boot Guard and Trusted Execution Technology



SB2022052312 - Security restrictions bypass in Intel Boot Guard and Trusted Execution Technology

Published: May 23, 2022

Security Bulletin ID SB2022052312
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2022-0004)

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to hardware debug modes and processor INIT setting allow to override of locks for some Intel Processors in Intel Boot Guard and Intel Trusted Execution Technology. An unauthenticated attacker with physical access to the system can bypass implemented security restrictions and escalate privileges on the system.

The vulnerability can be also exploited remotely by an authenticated attacker on the local network.


Remediation

Install update from vendor's website.