Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Enclave OS Virtual, which runs container workloads within confidential virtual machines. The issue allows an attacker, by intercepting an enclave's private key, to present a fake connection as legitimate to a trusting party, potentially leading to the acceptance of untrusted sessions. The main concern is to confirm if this specific technology is in use within the organization.
- A flaw could allow fake connections to be trusted.
- Understanding its relevance is the primary leadership concern.
- Assess if this technology is deployed within your environment.
Attack Path
How an attacker could exploit the issue
An attacker could gain unauthorized access by obtaining a confidential virtual machine's private key. They would then relay a legitimate security quote to a different connection, tricking the relying party into trusting a malicious session as if it were from the genuine virtual machine. This attack targets the remote attestation process within confidential computing environments.
- Attacker obtains enclave private key.
- Relays a genuine quote to another connection.
- Relying party trusts attacker's connection.
Live Threat
Current exploitation, exposure, and threat context
A vulnerability exists in Enclave OS Virtual that could allow an attacker to impersonate an attested enclave when a relying party validates a certificate. This occurs when the certificate public-key hash and client nonce are included in the quote's ReportData but a value bound to the active TLS session is omitted, provided the attacker has obtained an enclave TLS private key and the relying party is vulnerable to a relayed quote.
- Enclave TLS private keys.
- Attacker relays a genuine quote.
- Relying party accepts fake connection.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Enclave OS Virtual, likely managed by platform or infrastructure teams responsible for confidential computing environments. The first step is to identify all instances of Enclave OS Virtual, confirm their network reachability and business criticality, and then determine the accountable owner for remediation.
- Platform or infrastructure teams own remediation.
- Verify affected Enclave OS Virtual instances.
- Plan upgrades during maintenance windows.