Skip to main content

CVE detail

CVE-2017-5753

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVSS 5.6 · MediumBuzz score 46.0

Buzz score

Why this CVE is surfacing

Buzz score total 46.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
58 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
58 source links · newest first
  • In January 2018, the entire computer industry was put on alert by two new processor vulnerabilities dubbed Meltdown and Spectre that defeated the fundamental OS security boundaries separating kernel and user space memory. The flaws stemmed from a performance feature of modern CPUs known as speculative execution and mitigating them required one of the biggest patch coordination […]

    newswww.csoonline.comJul 15, 2024, 5:59 AM
  • The last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]

    newswww.csoonline.comJul 19, 2022, 9:00 AM
  • Spook.js is a new side-channel attack on modern processors that can allow bypassing Site Isolation protections implemented in Google Chrome. Boffins devised a transient side-channel attack on modern processors, “Spook.js,” that can be abused by threat actors to bypass Site Isolation protections implemented in Google Chrome and Chromium browsers. The technique allows in some cases to steal sensitive […]

    newssecurityaffairs.comSep 13, 2021, 3:26 PM
  • Linux kernel recently fixed a couple of vulnerabilities that could allow an attacker to bypass mitigations designed to protect devices against Spectre attacks. Kernel updates released in March have addressed a couple of vulnerabilities that could be exploited by an attacker to bypass mitigations designed to protect devices against Spectre attacks. In January 2018, White […]

    newssecurityaffairs.comMar 30, 2021, 2:28 PM
  • Google released proof-of-concept code to conduct Spectre attacks against its Chrome browser to share knowledge of browser-based side-channel attacks. Google released proof-of-concept code for conducting a Spectre attack against its Chrome browser on GitHub. The experts decided to publish the proof of concept code to demonstrate the feasibility of a web-based Spectre exploit. The PoC […]

    newssecurityaffairs.comMar 14, 2021, 9:49 AM
  • A researcher revealed on Monday that some exploits for the notorious CPU vulnerability known as Spectre were uploaded recently to the VirusTotal malware analysis service. While some experts say this could increase the risk of exploitation for malicious purposes, others believe there is no reason for concern.

    newswww.securityweek.comMar 3, 2021, 12:22 PM
  • The Spectre and Meltdown vulnerabilities discovered in January 2018 showed that weaknesses in CPUs were a potential attack vector. They allow a rogue process to read memory without authorization. Patches were rolled out along with bios updates from the manufacturer, but they came with a costly side effect: They degraded performance, especially on systems with […]

    newswww.csoonline.comMay 29, 2019, 10:00 AM
  • Microsoft started rolling out a new software update for Windows 10 systems to apply mitigations against the Spectre attacks. Over the weekend, Microsoft started distributing software updates for Windows 10 systems to enable the Retpoline mitigations against Spectre attacks. In January 2018 security experts at Google Project Zero disclosed Meltdown and Spectre side-channel attacks that […]

    newssecurityaffairs.comMar 5, 2019, 7:44 AM
  • Over the weekend, Microsoft started rolling out a new software update for Windows 10 devices to enable the Retpoline mitigations against Spectre attacks.

    newswww.securityweek.comMar 4, 2019, 6:37 PM
  • In January 2018, security news media was abuzz over a new class of vulnerability called side channel vulnerabilities. Spectre, Meltdown and Foreshadow are some of the best known. They exploit weaknesses in speculative execution in microprocessors to leak unauthorized information. Side channel vulnerabilities allow attackers to bypass account permissions, virtualization boundaries and protected memory regions. […]

    newswww.csoonline.comFeb 20, 2019, 11:00 AM
  • Researchers who devised the original Meltdown and Spectre attacks disclosed seven new variants that leverage on a technique known as transient execution. In January, white hackers from Google Project Zero disclosed the vulnerabilities that potentially impact all major CPUs, including the ones manufactured by AMD, ARM, and Intel. The expert devised two attacks dubbed Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 and CVE-2017-5715), which could […]

    newssecurityaffairs.comNov 14, 2018, 10:58 PM
  • On May 21, 2018, Google Project Zero (GPZ), Microsoft and Intel disclosed two new Spectre- and Meltdown-related chip vulnerabilities: Speculative Store Bypass (SSB) and Rogue System Registry Read. The customer risk from both disclosures is low. Then on June 13, 2018, Intel released a security advisory on the Lazy FP State Restore vulnerability, CVE-2018-3665, involving […]

    newswww.csoonline.comAug 1, 2018, 10:00 AM
  • Researchers discovered a new variant of the Spectre attack, dubbed NetSpectre, that allows to steal data over the network from the target system. A group of researchers has devised a new variant of the Spectre attack, dubbed NetSpectre, that could allow an attacker to steal data over the network from the target system. NetSpectre is described as […]

    newssecurityaffairs.comJul 27, 2018, 6:53 PM
  • Siemens recently updated its security bulletin for the Meltdown and Spectre vulnerabilities to inform customers of the latest variants, specifically the ones known as LazyFP and Spectre 1.1.

    newswww.securityweek.comJul 17, 2018, 7:10 PM
  • A team of researchers has discovered new variant of the famous Spectre attack (Spectre 1.1), and Intel has paid a $100,000 bug bounty as part of its bug bounty program. Intel has paid out a $100,000 bug bounty for new vulnerabilities that are related to the first variant of the Spectre attack (CVE-2017-5753), for this reason, […]

    newssecurityaffairs.comJul 11, 2018, 5:18 PM
  • Researchers have discovered new variations of the Spectre attack and they received $100,000 from Intel through the company’s bug bounty program. The new flaws are variations of Spectre Variant 1 (CVE-2017-5753) and they are tracked as Spectre 1.1 (CVE-2018-3693) and Spectre 1.2.

    newswww.securityweek.comJul 11, 2018, 5:13 AM
  • Updates released by Microsoft on Tuesday for its Windows operating system add support for a feature that should prevent attacks involving the recently disclosed speculative execution vulnerability known as “Variant 4.”

    newswww.securityweek.comJun 13, 2018, 5:47 AM
  • Yesterday AMD, ARM, IBM, Intel, Microsoft and other major tech firms released updates, mitigations and published security advisories for two new variants of Meltdown and Spectre attacks. Spectre and Meltdown made the headlines again, a few days after the disclosure of a new attack technique that allowed a group of researchers to recover data from the System […]

    newssecurityaffairs.comMay 22, 2018, 8:04 AM
  • Intel, AMD, ARM, IBM, Microsoft and other major tech companies on Monday released updates, mitigations and advisories for two new variants of the speculative execution attack methods known as Meltdown and Spectre.

    newswww.securityweek.comMay 22, 2018, 5:34 AM
  • Researchers from Eclypsium proposed a new variation of the Spectre attack that can allow attackers to recover data stored inside CPU System Management Mode. Security experts from Eclypsium have devised a new variation of the Spectre attack that can allow attackers to recover data stored inside CPU System Management Mode (SMM) (aka called ring -2). The SMM is an operating […]

    newssecurityaffairs.comMay 20, 2018, 7:39 AM
  • As part of its May 2018 Android Security Bulletin, Google this week released additional mitigations for the Meltdown attack that impacts microprocessors from Intel, AMD, and other vendors.

    newswww.securityweek.comMay 9, 2018, 11:52 AM
  • A group of security researchers has reportedly discovered 8 new varieties of the Spectre vulnerabilities, dubbed Spectre-Next Generation or Spectre-NG, that affect Intel CPUs. A German security website reported that an unnamed team of researchers has discovered the new flaws that exploit the new issues reported in the original Spectre and Meltdown attacks. The new eight Spectre-NG vulnerabilities in Intel CPUs also affect some ARM […]

    newssecurityaffairs.comMay 5, 2018, 9:53 AM
  • Microsoft this week released another round of software and microcode updates designed to address the CPU vulnerability known as Spectre Variant 2. Microsoft has been releasing software mitigations for the Spectre and Meltdown vulnerabilities since January, shortly after researchers disclosed the flaws.

    newswww.securityweek.comApr 26, 2018, 7:29 AM
  • AMD released patches for Spectre Variant 2 attack that includes both microcode and operating system updates. AMD and Microsoft worked together to issue the updates on Tuesday. AMD and Microsoft released the microcode and security updates for Spectre vulnerabilities. The Meltdown and Spectre attacks could be exploited by attackers to bypass memory isolation mechanisms and access target sensitive […]

    newssecurityaffairs.comApr 11, 2018, 10:52 AM
  • AMD and Microsoft on Tuesday released microcode and operating system updates that should protect users against Spectre attacks.

    newswww.securityweek.comApr 11, 2018, 5:34 AM
  • Google announced that mitigations for devices with Intel processors that are affected by the Spectre and Meltdown vulnerabilities will be available for latest stable channel update for Google’s Chrome OS operating system. The Meltdown and Spectre attacks could be exploited by attackers to bypass memory isolation mechanisms and access target sensitive data. The Meltdown attack could allow attackers to read […]

    newssecurityaffairs.comMar 22, 2018, 6:27 PM
  • The latest stable channel update for Google’s Chrome OS operating system includes mitigations for devices with Intel processors affected by the Spectre and Meltdown vulnerabilities.

    newswww.securityweek.comMar 22, 2018, 2:36 PM
  • Intel announced on Thursday that patches designed to address the Spectre vulnerability are now available for all the affected CPUs released in the past five years, and shared more details on the future processors that will include protections against these types of attacks.

    newswww.securityweek.comMar 15, 2018, 8:17 PM
  • Microsoft informed users on Tuesday that it released additional patches for the CPU vulnerabilities known as Meltdown and Spectre, and removed antivirus compatibility checks in Windows 10.

    newswww.securityweek.comMar 14, 2018, 2:25 PM
  • Microsoft announced on Thursday that Windows users will receive the microcode updates released by Intel to patch the notorious Spectre vulnerability.

    newswww.securityweek.comMar 2, 2018, 7:07 AM
  • Intel has released new firmware updates for its Broadwell and Haswell processors to address the Spectre vulnerability. After the first round of Spectre patches released by the company caused more frequent reboots and other instability problems, Intel started working on new microcode updates.

    newswww.securityweek.comFeb 28, 2018, 9:13 AM
  • Intel has released firmware updates that fix the Spectre vulnerability for many of its processors and patches for dozens more are nearly ready for use in production environments.

    newswww.securityweek.comFeb 21, 2018, 2:34 PM
  • IBM has released firmware and operating system updates to address the Meltdown and Spectre vulnerabilities in the company’s Power Systems servers.

    newswww.securityweek.comFeb 12, 2018, 2:09 PM
  • Intel is releasing new firmware updates that should address Spectre vulnerabilities CVE-2017-5715 for Skylake processors. Intel is releasing new firmware updates limited to Skylake processors to address Spectre vulnerabilities, patches for other platforms are expected very soon. The Spectre attack allows user-mode applications to extract information from other processes running on the same system. It can also be exploited […]

    newssecurityaffairs.comFeb 8, 2018, 8:24 AM
  • Out-of-band Windows updates released by Microsoft over the weekend disable mitigations for one of the Spectre attack variants as they can cause systems to become unstable.

    newswww.securityweek.comJan 29, 2018, 6:07 AM
  • Dell, HP and other system manufacturers have advised customers not to install the recent BIOS updates designed to address the Spectre and Meltdown CPU vulnerabilities due to unstable code delivered by Intel.

    newswww.securityweek.comJan 23, 2018, 6:38 PM
  • The recently disclosed Spectre and Meltdown vulnerabilities, which affect hardware running in the majority of the world’s computing devices have made headlines recently. The list of at risk equipment includes workstations, servers, phones, tablets, as well as Microsoft Windows, Linux, Android, Google ChromeOS, Apple macOS on most Intel chips manufactured after 2010.

    newswww.securityweek.comJan 23, 2018, 1:41 PM
  • Red Hat has decided to pull microcode patches for one variant of the Spectre exploit after users complained that updates had caused their systems to stop booting.

    newswww.securityweek.comJan 22, 2018, 3:38 PM
  • Oracle rolled out the January 2018 Critical Patch Update that includes 237 security fixes in its products, the majority of which is remotely exploitable without authentication. The January 2018 Critical Patch Update also includes security updates that address Spectre and Meltdown vulnerabilities. “The January 2018 Critical Patch Update provides fixes for certain Oracle products for the […]

    newssecurityaffairs.comJan 17, 2018, 3:06 PM
  • Oracle on Tuesday released its first Critical Patch Update for 2018 to deliver 237 new security fixes across its product portfolio. Over half of the addressed vulnerabilities could be remotely exploited without authentication.

    newswww.securityweek.comJan 17, 2018, 12:32 PM
  • Acer, Asus, Dell, Fujitsu, HP, IBM, Lenovo, Panasonic, Toshiba and other device manufacturers have started releasing BIOS updates that should patch the recently disclosed Spectre and Meltdown vulnerabilities.

    newswww.securityweek.comJan 15, 2018, 10:04 AM
  • AMD has informed customers that it will soon release processor microcode updates that should mitigate one of the recently disclosed Spectre vulnerabilities, and Microsoft has resumed delivering security updates to devices with AMD CPUs.

    newswww.securityweek.comJan 12, 2018, 7:11 AM
  • Canonical was forced to release a second round of Ubuntu updates that address the recently disclosed CPU vulnerabilities after some users complained that their systems no longer booted after installing the initial patches.

    newswww.securityweek.comJan 11, 2018, 4:03 PM
  • NVIDIA has released updates for its GPU display drivers and other products in an effort to mitigate the recently disclosed attack methods dubbed Meltdown and Spectre.

    newswww.securityweek.comJan 10, 2018, 8:50 PM
  • Last week, the disclosure by multiple teams from Graz and Pennsylvania University, Rambus, Data61, Cyberus Technology, and Google Project Zero of…

    newswww.malwarebytes.comJan 10, 2018, 5:00 PM
  • Microsoft and Intel have shared more information on the performance impact of the patches released for the recently disclosed attack methods known as Spectre and Meltdown.

    newswww.securityweek.comJan 10, 2018, 9:13 AM
  • Apple released iOS 11.2.2 software, a macOS High Sierra 10.13.2 supplemental update, and Safari 11.0.2 to fix Spectre flaws. On Monday, Apple released patches to fix Spectre flaws in Safari, macOS, and iOS, the tech giant released iOS 11.2.2 software a macOS High Sierra 10.13.2 supplemental update. The patches also fixed vulnerabilities in Apple WebKit, the web […]

    newssecurityaffairs.comJan 9, 2018, 12:43 PM
  • Updates released by Apple on Monday for iOS, macOS and Safari should mitigate the effects of the vulnerabilities exploited by the recently disclosed attack method named Spectre.

    newswww.securityweek.comJan 9, 2018, 6:09 AM
  • Qualcomm has confirmed that some of its products are affected by the recently disclosed Spectre and Meltdown vulnerabilities , but the company says mitigations are being deployed.

    newswww.securityweek.comJan 8, 2018, 8:36 AM
  • Cisco is going to release security patches for Meltdown and Spectre attacks, the company is currently investigating its entire products portfolio. Cisco published a security advisory on the CPU Side-Channel information disclosure vulnerabilities that are exploited in the Spectre and Meltdown attacks and announced it is going to release security updates to protect its customers. Switchzilla announced it […]

    newssecurityaffairs.comJan 6, 2018, 11:18 AM
  • Apple has confirmed that it has already pushed out security updates for iOS, macOS and tvOS that mitigate the danger of users being affected by Meltdown attacks. (watchOS did not require mitigation.) The updates were released in early December, and apparently there is no measurable reduction in the performance of macOS and iOS due to the implementation of the mitigations. But, when it comes to reducing the risk of Spectre attacks, updates are yet to … More →

    newswww.helpnetsecurity.comJan 5, 2018, 4:24 PM
  • Meltdown and Spectre attacks – According to Intel, by the end of the next week, the company will have issued security patches for more than 90% of chips commercialized in the past 5 years. White hat hackers from Google Project Zero this week disclosed the details of Meltdown and Spectre attacks targeting CPUs from major manufacturers, […]

    newssecurityaffairs.comJan 5, 2018, 2:45 PM
  • Update: Please note, Microsoft has suspended Windows security updates related to this issue on systems with older AMD CPUs, after a documentation mix-up led to the systems being unable to boot after patches were applied. Support forum posts are centered mostly on older Sempron and Athlon chips, the largest thread on the issue has more […]

    newswww.csoonline.comJan 4, 2018, 11:08 PM
  • Get an overview of the Meltdown and Spectre vulnerabilities including a risk assessment and calls to action.

    vendorunit42.paloaltonetworks.comJan 4, 2018, 9:25 PM
  • In the wake of yesterday’s news and speculation about a serious design flaw in Intel processors, the security researchers involved in discovering the issue and the companies affected have started releasing details about it and about their mitigation efforts. As it turns out, there are two separate attacks that can result in exploitation of different issues: Meltdown – exploits CVE-2017-5754, and can lead to rogue data cache load Spectre – exploits CVE-2017-5753 and CVE-2017-5715, and … More →

    newswww.helpnetsecurity.comJan 4, 2018, 7:31 PM
  • The Meltdown and Spectre attacks could allow attackers to steal sensitive data which is currently processed on the computer. Almost every modern processor is vulnerable to the ‘memory leaking’ flaws, this has emerged from technical analysis triggered after the announcement of vulnerabilities in Intel Chips. White hackers from Google Project Zero have disclosed the vulnerabilities that potentially impact […]

    newssecurityaffairs.comJan 4, 2018, 3:15 PM
  • Several major tech companies have started releasing patches and mitigations for the recently disclosed Meltdown and Spectre vulnerabilities affecting CPUs from Intel, AMD and ARM.

    newswww.securityweek.comJan 4, 2018, 1:21 PM
  • Details of “Meltdown” and “Spectre” Attacks Against Intel and AMD Chips Disclosed

    newswww.securityweek.comJan 3, 2018, 10:20 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence