CVE-2018-3626: Intel Sgx SDK

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.

Affected products

  • Intel Sgx SDK: before 1.9.6 (fixed in 1.9.6); before 2.1.2 (fixed in 2.1.2)

Published 2018-03-20. Last modified 2026-06-17.