Executive brief
A security vulnerability exists in certain Intel Pentium and Celeron processors (Gemini Lake) that use a default cryptographic key. An attacker with physical access to the hardware and specialized technical knowledge could potentially bypass security protections to gain elevated system privileges. This could lead to the unauthorized access of sensitive data protected by Intel SGX technology.
Technical details
This vulnerability (CWE-1394) involves the use of a default cryptographic key within the hardware of specific Intel Gemini Lake processors (Pentium Silver, Celeron J, and Celeron N series). An attacker acting as a hardware reverse engineer with physical access and administrative privileges can exploit this flaw through a high-complexity attack. The root cause is related to the Intel Trace Hub and impacts Intel SGX device-specific keys. Successful exploitation allows for escalation of privilege and high impacts on confidentiality and integrity. Intel has stated they will not provide additional firmware mitigations for these chipsets and instead recommends enabling Firmware Version Control and preventing unauthorized physical access.
Affected products
- Intel Pentium Processor Silver Series CPUID 706A1, 706A8 (Gemini Lake)
- Intel Celeron Processor J Series CPUID 706A1, 706A8 (Gemini Lake)
- Intel Celeron Processor N Series CPUID 706A1, 706A8 (Gemini Lake)
- Intel Trace Hub Various (see advisory)
Timeline
- 2022-03-08: disclosed: Initial release of INTEL-SA-00609 regarding CVE-2021-33150
- 2026-04-01: other: Intel became aware of the issue via social media reports regarding SGX key extraction
- 2026-04-08: advisory: Updated advisory released including CVE-2026-20709