Executive brief
Intel Data Center Attestation Primitives (DCAP) is a software library used by data center operators to verify the integrity and authenticity of Intel processors in remote attestation scenarios. A vulnerability in the Quote Verification Library component allows an unprivileged attacker with network access to bypass integrity measurements and disclose sensitive information, potentially compromising the security assurances that customers rely on for confidential computing workloads.
Technical details
A protection mechanism failure in Intel DCAP's Quote Verification Library (QVL) component allows integrity measurement bypass and information disclosure. The vulnerability is exploitable by an unauthenticated, unprivileged attacker via network access with low attack complexity and special internal knowledge, requiring no user interaction. An attacker can compromise the integrity of measurements (VI:H) with subsequent high confidentiality impact to the system (SC:H), effectively undermining the attestation guarantees. Patches are available in version 1.25 and later; systems running affected versions 1.20 through 1.24 should be updated immediately.
Affected products
- Intel Data Center Attestation Primitives 1.20 through 1.24
Timeline
- 2026-08-11: disclosed