Remote Attestation Reports Security Vulnerabilities even when Latest Microcode is Installed
Content Type: Error Messages | Article ID: 000057653 | Last Reviewed: 07/26/2021
The microcode files available from the Intel Linux Processor Microcode Files GitHub repository are operating system (OS) microcode updates but Intel® Software Guard Extensions (Intel® SGX) mitigations require early load microcode available in BIOS.
Follow these steps to mitigate Intel SGX issues:
The article Loading Microcode from the OS contains more information on the different types of microcode.
The Intel® Software Guard Extensions (Intel® SGX) SDK information is included in the Quote that the platform sends to the relying third party.
Note | If you already have the latest Intel® Software Guard Extensions (Intel® SGX) SDK and the latest Intel SGX PSW and are still encountering SA-00293, it may be because other vulnerabilities are still unmitigated. |