Wiz Agents & Workflows are here

CVE-2023-49141
Bottlerocket vulnerability analysis and mitigation

Overview

CVE-2023-49141 is a high-severity vulnerability discovered in Intel® Processors' stream cache mechanism. The vulnerability involves improper isolation that could potentially allow an authenticated user to escalate privileges through local access. This security flaw was discovered internally by Intel employees and was publicly disclosed on August 13, 2024 (Intel Advisory).

Technical details

The vulnerability has received a CVSS Base Score 3.1 of 7.8 (High) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H. The technical assessment indicates that while the attack vector is local and requires high attack complexity, it can lead to significant impacts on confidentiality, integrity, and availability. The vulnerability specifically affects the stream cache mechanism in various Intel processor families (Intel Advisory).

Impact

The vulnerability can potentially lead to escalation of privilege, affecting multiple Intel processor families including 4th Generation Intel® Xeon® Scalable processors, Intel® Xeon® CPU Max Series processors, Intel® Xeon® W2400 and W3400 Processors, and various generations of Intel® Core™ Processor families. The impact spans across server, workstation, mobile, and desktop platforms (Intel Advisory).

Mitigation and workarounds

Intel has released microcode updates to mitigate this vulnerability. Users of affected Intel® Processors are recommended to update to the latest version firmware provided by their system manufacturer. The microcode updates are available through Intel's public GitHub repository and can be OS loaded (Intel Advisory).

Additional resources


SourceThis report was generated using AI

Related Bottlerocket vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-45492CRITICAL9.8
  • BottlerocketBottlerocket
  • expat
NoYesAug 30, 2024
CVE-2024-45491CRITICAL9.8
  • BottlerocketBottlerocket
  • thunderbird
NoYesAug 30, 2024
CVE-2022-21505MEDIUM6.7
  • NixOSNixOS
  • kernel-tools-debuginfo
NoYesDec 24, 2024
CVE-2022-28693MEDIUM4.7
  • Linux KernelLinux Kernel
  • kernel-debuginfo-common-i686
NoYesFeb 14, 2025
CVE-2024-45310LOW3.6
  • cAdvisorcAdvisor
  • kubevirt-virtctl
NoYesSep 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management