CVE-2009-0066
Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot. NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- intel/trusted execution technology
- Source
- cve@mitre.org
References
- http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk
- http://invisiblethingslab.com/press/itl-press-2009-01.pdf
- http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html
- http://www.securityfocus.com/bid/33119
- http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk
- http://invisiblethingslab.com/press/itl-press-2009-01.pdf
- http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html
- http://www.securityfocus.com/bid/33119
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.