Rewterz
Rewterz Threat Alert – APT MustangPanda – Active IOCs
February 11, 2022
Rewterz
Rewterz Threat Alert – Bitter APT Group – Active IOCs
February 11, 2022

Rewterz Threat Advisory – Multiple Intel Trace Analyzer and Collector Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-21156

Intel Trace Analyzer and Collector is vulnerable to a denial of service, caused by an access of an uninitialized pointer. A local attacker could exploit this vulnerability cause a denial of service.

CVE-2022-21218

Intel Trace Analyzer and Collector could allow a local attacker to obtain sensitive information, caused by uncaught exception. An attacker could exploit this vulnerability to obtain sensitive information.

CVE-2022-21226

Intel Trace Analyzer and Collector could allow a local attacker to obtain sensitive information, caused by out-of-bounds read. An attacker could exploit this vulnerability to obtain sensitive information.

Impact

  • Denial of Service
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2022-21156
  • CVE-2022-21218
  • CVE-2022-21226

Affected Vendors

Intel

Affected Products

  • Intel Trace Analyzer and Collector 2021.5

Remediation

Refer to INTEL Security Advisory for patch, upgrade or suggested workaround information.

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00639.html