5.5
CVSSv3

CVE-2020-8944

Published: 15/12/2020 Updated: 17/12/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted malicious user to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google asylo