CVE-2024-45332: Information Disclosure in Intel(R) Processors
CVE-2024-45332 is a medium severity information disclosure vulnerability affecting certain Intel processors including CascadeLake, Ice Lake XeonSP, Ice Lake XeonD, Sapphire Rapids, and Emerald Rapids. The vulnerability is a side channel issue reported by Intel and addressed by Google in their cloud infrastructure. No evidence of exploitation has been found or reported. Google has applied fixes to protect customers, and no customer action is required at this time.
AI Analysis
Technical Summary
CVE-2024-45332 is a side channel information disclosure vulnerability impacting multiple Intel processor families: CascadeLake, Ice Lake XeonSP, Ice Lake XeonD, Sapphire Rapids, and Emerald Rapids. Intel notified Google about this vulnerability, and Google has implemented mitigations in their cloud environment to protect affected assets. The vulnerability has a CVSS 4.0 base score of 5.7, indicating medium severity, with attack vector local, high complexity, and partial privileges required. There is no current evidence of active exploitation. The Intel advisory INTEL-SA-01247 provides further details.
Potential Impact
The vulnerability could allow an attacker with local access and partial privileges to obtain sensitive information through a side channel attack on affected Intel processors. However, the impact is limited by the requirement for local access and high attack complexity. No exploitation has been observed in the wild, and Google has already applied fixes in their cloud infrastructure to mitigate the risk for their customers.
Mitigation Recommendations
Google has applied fixes to the affected assets in their cloud environment, including Google Cloud, to protect customers. No customer action is required at this time. Users of affected Intel processors should monitor Intel's advisory INTEL-SA-01247 for any updates or official patches. Patch status for other environments is not explicitly stated; check vendor advisories for current remediation guidance.
CVE-2024-45332: Information Disclosure in Intel(R) Processors
Description
CVE-2024-45332 is a medium severity information disclosure vulnerability affecting certain Intel processors including CascadeLake, Ice Lake XeonSP, Ice Lake XeonD, Sapphire Rapids, and Emerald Rapids. The vulnerability is a side channel issue reported by Intel and addressed by Google in their cloud infrastructure. No evidence of exploitation has been found or reported. Google has applied fixes to protect customers, and no customer action is required at this time.
CVSS v4.0
Score 5.7medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-45332 is a side channel information disclosure vulnerability impacting multiple Intel processor families: CascadeLake, Ice Lake XeonSP, Ice Lake XeonD, Sapphire Rapids, and Emerald Rapids. Intel notified Google about this vulnerability, and Google has implemented mitigations in their cloud environment to protect affected assets. The vulnerability has a CVSS 4.0 base score of 5.7, indicating medium severity, with attack vector local, high complexity, and partial privileges required. There is no current evidence of active exploitation. The Intel advisory INTEL-SA-01247 provides further details.
Potential Impact
The vulnerability could allow an attacker with local access and partial privileges to obtain sensitive information through a side channel attack on affected Intel processors. However, the impact is limited by the requirement for local access and high attack complexity. No exploitation has been observed in the wild, and Google has already applied fixes in their cloud infrastructure to mitigate the risk for their customers.
Mitigation Recommendations
Google has applied fixes to the affected assets in their cloud environment, including Google Cloud, to protect customers. No customer action is required at this time. Users of affected Intel processors should monitor Intel's advisory INTEL-SA-01247 for any updates or official patches. Patch status for other environments is not explicitly stated; check vendor advisories for current remediation guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- intel
- Date Reserved
- 2024-09-19T03:00:23.104Z
- Cisa Enriched
- true
- Cvss Version
- 4.0
- State
- PUBLISHED
- Source Type
- Subreddit
- netsec
- Reddit Score
- 31
- Discussion Level
- minimal
- Content Source
- external_link
Threat ID: 682cd0fb1484d88663aecab8
Added to database: 05/20/2025, 18:59:07 UTC
Last enriched: 08/04/2026, 13:27:45 UTC
Last updated: 08/05/2026, 00:41:06 UTC
Views: 115
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.