CVE-2019-1369 — Open Enclave SDK Information Disclosure Vulnerability
Executive Summary
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information stored in the Enclave. To exploit this vulnerability, an attacker would have to successfully compromise the host application running the enclave. The attacker can then pivot to the enclave and exploit this vulnerability without user interaction. The security update addresses the vulnerability by modifying how Open Enclave SDK handle objects in memory.
Overview
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Open Enclave SDK | Release Notes (Security Update) |
Important | Information Disclosure | Maybe |
Patches
| Article | Type | Restart |
|---|---|---|
Release Notes |
Security Update | Maybe |
Known Exploits
Acknowledgments
David Oswald (The University of Birmingham, UK), Jo van Bulck (imec-DistriNet, KU Leuven), Frank Piessens (imec-DistriNet, KU Leuven), Abdulla Aldoseri (The University of Birmingham, UK), Eduard Marin (The University of Birmingham, UK), Flavio Garcia (The University of Birmingham, UK), Mark Ryan (The University of Birmingham, UK)