Arbitrary enclave memory overwrite vulnerability in ECall ecall_restore
Vulnerability Description
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params and allowed the host to return a pointer that was an address within the enclave memory. This allowed an attacker to read memory values from within the enclave.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8936
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Qinkun Bao (Baidu Security)
- Zhaofeng Chen (Baidu Security)
- Mingshen Sun (Baidu Security)
- Kang Li (Baidu Security)
More from Google LLC
View All →Affected Vendor
Google LLC
View all reports →