QID 375715
Date Published: 2021-07-14
QID 375715: Open Enclave Software Development Kit (SDK) Elevation of Privilege Vulnerability July 2021
Enclaves have a vulnerability that provides a brief window for a local attacker to hijack the control flow of execution by controlling the input parameters. A malicious host can create an exception immediately after EENTER which causes control to be transferred to the host before the enclave stack(RSP register) has been set up. The host can then transfer control back to the enclave and cause it to execute with a stack that resides in host memory thereby enabling ROP exploits.
Affected Software:
Open Enclave SDK version prior to 0.17.1
QID Detection Logic:
Checks for open-enclave package version less than 0.17.1
Successful exploitation allows elecation of privilege.
Solution
Customers are advised to refer to v0.17.1 or later for more details.
Vendor References
- CVE-2021-33767 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33767
CVEs related to QID 375715
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| v0.17.1 |
|