An arbitrary memory overwrite vulnerability in Asylo versions up to...
Vulnerability Description
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8935
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Qinkun Bao (Baidu Security)
- Zhaofeng Chen (Baidu Security)
- Mingshen Sun (Baidu Security)
- Kang Li (Baidu Security)
More from Google LLC
View All →Affected Vendor
Google LLC
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.