Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade microcode_ctlUpgrade microcode_ctl-debuginfo | May 13, 2024 | May 12, 2022 |
| Amazon_linux | — | Upgrade microcode_ctl | May 10, 2024 | May 12, 2022 |
| Amazon_linux_2023 | — | Upgrade microcode_ctl | Feb 17, 2025 | May 10, 2022 |
| Debian | — | Upgrade intel-microcode | Jul 30, 2024 | May 12, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 12, 2022 |
| Ubuntu | — | Upgrade intel-microcodeUpgrade intel-microcode (Ubuntu Pro) | Mar 22, 2023 | May 12, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub