CVE-2017-5753 EXPLOIT
5.6
MEDIUM · CVSS 3.1 · EPSS 93.8% (pctl 100)
Patch early
A public exploit exists.
Description
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scoring
| CVSS | 5.6 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 93.84% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-203 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-04 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| intel | atom c |
| intel | atom e |
| intel | atom x3 |
| intel | atom x5-e3930 |
| intel | atom x5-e3940 |
| intel | atom x7-e3950 |
| intel | atom z |
| intel | celeron j |
| intel | celeron n |
| intel | core i3 |
| intel | core i5 |
| intel | core i7 |
| intel | core m |
| intel | core m3 |
| intel | core m5 |
| intel | core m7 |
| intel | pentium j |
| intel | pentium n |
| intel | xeon |
| intel | xeon bronze 3104 |
| intel | xeon bronze 3106 |
| intel | xeon e-1105c |
| intel | xeon e3 |
| intel | xeon e3 1105c v2 |
| intel | xeon e3 1125c |
| intel | xeon e3 1125c v2 |
| intel | xeon e3 1220 |
| intel | xeon e3 1220 v2 |
| intel | xeon e3 1220 v3 |
| intel | xeon e3 1220 v5 |
| intel | xeon e3 1220 v6 |
| intel | xeon e3 12201 |
| intel | xeon e3 12201 v2 |
| intel | xeon e3 1220l v3 |
| intel | xeon e3 1225 |
| intel | xeon e3 1225 v2 |
| intel | xeon e3 1225 v3 |
| intel | xeon e3 1225 v5 |
| intel | xeon e3 1225 v6 |
| intel | xeon e3 1226 v3 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Multiple CPUs - 'Spectre' Information Disclosure | 2018-01-03 |
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
- http://www.kb.cert.org/vuls/id/584653
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.securityfocus.com/bid/102371
- http://www.securitytracker.com/id/1040071
- http://xenbits.xen.org/xsa/advisory-254.html
- https://access.redhat.com/errata/RHSA-2018:0292
- https://access.redhat.com/security/vulnerabilities/speculativeexecution
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/
→ the Explorer · watch your stack · NVD