Database/Firmware, BMC & network fabric
Intel processors with SGX (EDECCSSA leaf): Improper access control on the EDECCSSA user leaf function lets
CVE-2024-36293Firmware, BMC & network fabriccurated
Impact
Improper access control on the EDECCSSA user leaf function lets an authenticated local user deny SGX service. EDECCSSA is the SGX2 instruction used for in-enclave exception handling, so this is reachable from ordinary enclave-adjacent code.
Who can reach it
Local authenticated user on an SGX-enabled host.
What to do
Microcode update and reboot; late-loadable at boot without an OEM BIOS release. Re-attest afterwards.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.