CVE-2020-8944 is an arbitrary memory write vulnerability affecting Google Asylo versions up to 0.6.0. An authenticated local attacker can exploit this flaw by crafting a malicious call to ecall_restore, leading to unauthorized writes to arbitrary memory addresses, including those within secure enclaves. While rated Medium severity (CVSS 5.5) due to its local attack vector and high integrity impact, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Organizations using affected Asylo versions are advised to upgrade past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.0CPE matchmatch criteria | cpe:2.3:a:google:asylo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.