CVE-2021-33767: Open Enclave SDK Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.2)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Jul
Released
2021-07-13
Last Updated
2021-07-13
EPSS Score
0.48% (percentile: 65.2%)

FAQ

How do I know if I'm affected by this vulnerability? If you have a project that used the Open Enclave SDK and you have not rebuilt it using the latest version of the SDK, you might be affected by this vulnerability. The updated SDK release is available here: Open Enclave Releases. Confirm that you are using SDK build v0.17.1 or later. For more information, see Open Enclave SDK Security Advisory for July 13, 2021.

Affected Products (1)

Developer Tools

  • Open Enclave SDK

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/corankyu">Zhijingcheng Yu</a> of <a href="https://www.comp.nus.edu.sg/~yuz1996/">National University of Singapore</a>, <a href="https://twitter.com/jhcui24">Jinhua Cui</a> of <a href="https://cimcs.github.io/">National University of Defense Technology and National University of Singapore</a>, <a href="https://twitter.com/prateekatcs">Prateek Saxena</a> of <a href="https://www.comp.nus.edu.sg/~prateeks/">National University of Singapore</a>, <a href="https://twitter.com/shw3ta_shinde">Shweta Shinde</a> of <a href="https://shwetashinde.org">ETH Zurich</a>

Revision History

  • 2021-07-13: Information published.
  • 2021-07-13: Updated FAQ information. This is an informational change only.