CVE detail
CVE-2017-5754
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
55 source links · newest first
In January 2018, the entire computer industry was put on alert by two new processor vulnerabilities dubbed Meltdown and Spectre that defeated the fundamental OS security boundaries separating kernel and user space memory. The flaws stemmed from a performance feature of modern CPUs known as speculative execution and mitigating them required one of the biggest patch coordination […]
newswww.csoonline.comJul 15, 2024, 5:59 AMThe last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]
newswww.csoonline.comJul 19, 2022, 9:00 AMSpook.js is a new side-channel attack on modern processors that can allow bypassing Site Isolation protections implemented in Google Chrome. Boffins devised a transient side-channel attack on modern processors, “Spook.js,” that can be abused by threat actors to bypass Site Isolation protections implemented in Google Chrome and Chromium browsers. The technique allows in some cases to steal sensitive […]
newssecurityaffairs.comSep 13, 2021, 3:26 PMLinux kernel recently fixed a couple of vulnerabilities that could allow an attacker to bypass mitigations designed to protect devices against Spectre attacks. Kernel updates released in March have addressed a couple of vulnerabilities that could be exploited by an attacker to bypass mitigations designed to protect devices against Spectre attacks. In January 2018, White […]
newssecurityaffairs.comMar 30, 2021, 2:28 PM- Google releases Spectre PoC code exploit for Chrome browserSecurity Affairs
Google released proof-of-concept code to conduct Spectre attacks against its Chrome browser to share knowledge of browser-based side-channel attacks. Google released proof-of-concept code for conducting a Spectre attack against its Chrome browser on GitHub. The experts decided to publish the proof of concept code to demonstrate the feasibility of a web-based Spectre exploit. The PoC […]
newssecurityaffairs.comMar 14, 2021, 9:49 AM The Spectre and Meltdown vulnerabilities discovered in January 2018 showed that weaknesses in CPUs were a potential attack vector. They allow a rogue process to read memory without authorization. Patches were rolled out along with bios updates from the manufacturer, but they came with a costly side effect: They degraded performance, especially on systems with […]
newswww.csoonline.comMay 29, 2019, 10:00 AM- Microsoft enabled Retpoline mitigations against the Spectre Variant 2 for Windows 10Security Affairs
Microsoft started rolling out a new software update for Windows 10 systems to apply mitigations against the Spectre attacks. Over the weekend, Microsoft started distributing software updates for Windows 10 systems to enable the Retpoline mitigations against Spectre attacks. In January 2018 security experts at Google Project Zero disclosed Meltdown and Spectre side-channel attacks that […]
newssecurityaffairs.comMar 5, 2019, 7:44 AM Over the weekend, Microsoft started rolling out a new software update for Windows 10 devices to enable the Retpoline mitigations against Spectre attacks.
newswww.securityweek.comMar 4, 2019, 6:37 PMIn January 2018, security news media was abuzz over a new class of vulnerability called side channel vulnerabilities. Spectre, Meltdown and Foreshadow are some of the best known. They exploit weaknesses in speculative execution in microprocessors to leak unauthorized information. Side channel vulnerabilities allow attackers to bypass account permissions, virtualization boundaries and protected memory regions. […]
newswww.csoonline.comFeb 20, 2019, 11:00 AM- Boffins discovered seven new Meltdown and Spectre attacksSecurity Affairs
Researchers who devised the original Meltdown and Spectre attacks disclosed seven new variants that leverage on a technique known as transient execution. In January, white hackers from Google Project Zero disclosed the vulnerabilities that potentially impact all major CPUs, including the ones manufactured by AMD, ARM, and Intel. The expert devised two attacks dubbed Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 and CVE-2017-5715), which could […]
newssecurityaffairs.comNov 14, 2018, 10:58 PM On May 21, 2018, Google Project Zero (GPZ), Microsoft and Intel disclosed two new Spectre- and Meltdown-related chip vulnerabilities: Speculative Store Bypass (SSB) and Rogue System Registry Read. The customer risk from both disclosures is low. Then on June 13, 2018, Intel released a security advisory on the Lazy FP State Restore vulnerability, CVE-2018-3665, involving […]
newswww.csoonline.comAug 1, 2018, 10:00 AM- Intel pays a $100K bug bounty for the new CPU Spectre 1.1 flawSecurity Affairs
A team of researchers has discovered new variant of the famous Spectre attack (Spectre 1.1), and Intel has paid a $100,000 bug bounty as part of its bug bounty program. Intel has paid out a $100,000 bug bounty for new vulnerabilities that are related to the first variant of the Spectre attack (CVE-2017-5753), for this reason, […]
newssecurityaffairs.comJul 11, 2018, 5:18 PM Updates released by Microsoft on Tuesday for its Windows operating system add support for a feature that should prevent attacks involving the recently disclosed speculative execution vulnerability known as “Variant 4.”
newswww.securityweek.comJun 13, 2018, 5:47 AM- Tech giants are all working on new Spectre and Meltdown attacks, so-called variant 3 and variant 4Security Affairs
Yesterday AMD, ARM, IBM, Intel, Microsoft and other major tech firms released updates, mitigations and published security advisories for two new variants of Meltdown and Spectre attacks. Spectre and Meltdown made the headlines again, a few days after the disclosure of a new attack technique that allowed a group of researchers to recover data from the System […]
newssecurityaffairs.comMay 22, 2018, 8:04 AM Intel, AMD, ARM, IBM, Microsoft and other major tech companies on Monday released updates, mitigations and advisories for two new variants of the speculative execution attack methods known as Meltdown and Spectre.
newswww.securityweek.comMay 22, 2018, 5:34 AMGoogle releases additional Meltdown mitigations for Android as part of the May 2018 Android Security Bulletin. The tech giant also addresses flaws in NVIDIA and Qualcomm components. Both Meltdown and Spectre attacks could be exploited by attackers to bypass memory isolation mechanisms and access target sensitive data. The Meltdown attack (CVE-2017-5754 vulnerability) could allow attackers to read the entire physical memory of the […]
newssecurityaffairs.comMay 9, 2018, 1:51 PMAs part of its May 2018 Android Security Bulletin, Google this week released additional mitigations for the Meltdown attack that impacts microprocessors from Intel, AMD, and other vendors.
newswww.securityweek.comMay 9, 2018, 11:52 AMThe problems with the mitigations for the Meltdown flaw continue a security researcher has demonstrated that the Meltdown patch in Windows 10 can be bypassed. The Windows Internals expert Alex Ionescu discovered that a Meltdown patch issued for Windows 10 is affected by a severe vulnerability that could be exploited to bypass it. “Calling NtCallEnclave returned back […]
newssecurityaffairs.comMay 4, 2018, 7:50 AMMicrosoft this week released another round of software and microcode updates designed to address the CPU vulnerability known as Spectre Variant 2. Microsoft has been releasing software mitigations for the Spectre and Meltdown vulnerabilities since January, shortly after researchers disclosed the flaws.
newswww.securityweek.comApr 26, 2018, 7:29 AM- AMD and Microsoft release microcode and operating system updates against Spectre flawSecurity Affairs
AMD released patches for Spectre Variant 2 attack that includes both microcode and operating system updates. AMD and Microsoft worked together to issue the updates on Tuesday. AMD and Microsoft released the microcode and security updates for Spectre vulnerabilities. The Meltdown and Spectre attacks could be exploited by attackers to bypass memory isolation mechanisms and access target sensitive […]
newssecurityaffairs.comApr 11, 2018, 10:52 AM - AMD, Microsoft Release Spectre PatchesSecurityWeek
AMD and Microsoft on Tuesday released microcode and operating system updates that should protect users against Spectre attacks.
newswww.securityweek.comApr 11, 2018, 5:34 AM Google announced that mitigations for devices with Intel processors that are affected by the Spectre and Meltdown vulnerabilities will be available for latest stable channel update for Google’s Chrome OS operating system. The Meltdown and Spectre attacks could be exploited by attackers to bypass memory isolation mechanisms and access target sensitive data. The Meltdown attack could allow attackers to read […]
newssecurityaffairs.comMar 22, 2018, 6:27 PMThe latest stable channel update for Google’s Chrome OS operating system includes mitigations for devices with Intel processors affected by the Spectre and Meltdown vulnerabilities.
newswww.securityweek.comMar 22, 2018, 2:36 PM- New Intel processors to have hardware-based protections against Meltdown, Spectre 2Help Net Security
Intel has officially pushed out microcode updates with Spectre and Meltdown mitigations for all of the processors it launched in the past five years. In addition to this, the company’s CEO announced new, redesigned processor lines that will start shipping later this year and will include hardware-based protection for Meltdown (exploiting CVE-2017-5754, a rogue cata cache load flaw) and variant 2 of Spectre (exploiting CVE-2017-5715, a branch target injection vulnerability). New silicon, new hardware protections … More →
newswww.helpnetsecurity.comMar 19, 2018, 8:03 PM Intel announced on Thursday that patches designed to address the Spectre vulnerability are now available for all the affected CPUs released in the past five years, and shared more details on the future processors that will include protections against these types of attacks.
newswww.securityweek.comMar 15, 2018, 8:17 PM- Microsoft kicks off bounty program for speculative execution bugsHelp Net Security
Microsoft wants security researchers to search for and report speculative execution side channel vulnerabilities (a hardware vulnerability class that affects CPUs from multiple manufacturers), as well as bugs that can be misused to bypass Windows and Azure Spectre and Meltdown mitigations. For their successful efforts, the company is ready to pay out as much as $250,000. A new bug bounty The bounty program for speculative execution side channel vulnerabilities was announced on Wednesday and will … More →
newswww.helpnetsecurity.comMar 15, 2018, 4:44 PM Microsoft informed users on Tuesday that it released additional patches for the CPU vulnerabilities known as Meltdown and Spectre, and removed antivirus compatibility checks in Windows 10.
newswww.securityweek.comMar 14, 2018, 2:25 PMMicrosoft announced on Thursday that Windows users will receive the microcode updates released by Intel to patch the notorious Spectre vulnerability.
newswww.securityweek.comMar 2, 2018, 7:07 AMIntel has released new firmware updates for its Broadwell and Haswell processors to address the Spectre vulnerability. After the first round of Spectre patches released by the company caused more frequent reboots and other instability problems, Intel started working on new microcode updates.
newswww.securityweek.comFeb 28, 2018, 9:13 AM- Intel Releases Spectre Patches for More CPUsSecurityWeek
Intel has released firmware updates that fix the Spectre vulnerability for many of its processors and patches for dozens more are nearly ready for use in production environments.
newswww.securityweek.comFeb 21, 2018, 2:34 PM IBM has released firmware and operating system updates to address the Meltdown and Spectre vulnerabilities in the company’s Power Systems servers.
newswww.securityweek.comFeb 12, 2018, 2:09 PMIntel is releasing new firmware updates that should address Spectre vulnerabilities CVE-2017-5715 for Skylake processors. Intel is releasing new firmware updates limited to Skylake processors to address Spectre vulnerabilities, patches for other platforms are expected very soon. The Spectre attack allows user-mode applications to extract information from other processes running on the same system. It can also be exploited […]
newssecurityaffairs.comFeb 8, 2018, 8:24 AMOut-of-band Windows updates released by Microsoft over the weekend disable mitigations for one of the Spectre attack variants as they can cause systems to become unstable.
newswww.securityweek.comJan 29, 2018, 6:07 AMApple on Tuesday released security updates for a majority of its products, and it patched the vulnerability that allows Meltdown attacks in earlier versions of its Mac operating system.
newswww.securityweek.comJan 24, 2018, 1:09 PMDell, HP and other system manufacturers have advised customers not to install the recent BIOS updates designed to address the Spectre and Meltdown CPU vulnerabilities due to unstable code delivered by Intel.
newswww.securityweek.comJan 23, 2018, 6:38 PMThe recently disclosed Spectre and Meltdown vulnerabilities, which affect hardware running in the majority of the world’s computing devices have made headlines recently. The list of at risk equipment includes workstations, servers, phones, tablets, as well as Microsoft Windows, Linux, Android, Google ChromeOS, Apple macOS on most Intel chips manufactured after 2010.
newswww.securityweek.comJan 23, 2018, 1:41 PM- Red Hat Pulls Spectre Patches Due to InstabilitySecurityWeek
Red Hat has decided to pull microcode patches for one variant of the Spectre exploit after users complained that updates had caused their systems to stop booting.
newswww.securityweek.comJan 22, 2018, 3:38 PM Oracle rolled out the January 2018 Critical Patch Update that includes 237 security fixes in its products, the majority of which is remotely exploitable without authentication. The January 2018 Critical Patch Update also includes security updates that address Spectre and Meltdown vulnerabilities. “The January 2018 Critical Patch Update provides fixes for certain Oracle products for the […]
newssecurityaffairs.comJan 17, 2018, 3:06 PMOracle on Tuesday released its first Critical Patch Update for 2018 to deliver 237 new security fixes across its product portfolio. Over half of the addressed vulnerabilities could be remotely exploited without authentication.
newswww.securityweek.comJan 17, 2018, 12:32 PMAcer, Asus, Dell, Fujitsu, HP, IBM, Lenovo, Panasonic, Toshiba and other device manufacturers have started releasing BIOS updates that should patch the recently disclosed Spectre and Meltdown vulnerabilities.
newswww.securityweek.comJan 15, 2018, 10:04 AM- Meltdown Patch Broke Some Ubuntu SystemsSecurityWeek
Canonical was forced to release a second round of Ubuntu updates that address the recently disclosed CPU vulnerabilities after some users complained that their systems no longer booted after installing the initial patches.
newswww.securityweek.comJan 11, 2018, 4:03 PM - NVIDIA Updates GPU Drivers to Mitigate CPU FlawsSecurityWeek
NVIDIA has released updates for its GPU display drivers and other products in an effort to mitigate the recently disclosed attack methods dubbed Meltdown and Spectre.
newswww.securityweek.comJan 10, 2018, 8:50 PM - Meltdown and Spectre fallout: patching problems persistMalwarebytes Labs
Last week, the disclosure by multiple teams from Graz and Pennsylvania University, Rambus, Data61, Cyberus Technology, and Google Project Zero of…
newswww.malwarebytes.comJan 10, 2018, 5:00 PM Microsoft and Intel have shared more information on the performance impact of the patches released for the recently disclosed attack methods known as Spectre and Meltdown.
newswww.securityweek.comJan 10, 2018, 9:13 AM- Detection of the Meltdown and Spectre VulnerabilitiesCheck Point Research
Research By: Erez Israel, Daniel Marx, Yoav Alon, Aviv Gafni and Ben Omelchenko Last week, two publications regarding a pair of vulnerabilities named individually by their publishers as Meltdown and Spectre sent shockwaves through the cyber-security ecosystem. Using side-channel attacks, these vulnerabilities allow an attacker to break the security that lies at the core […]
vendorresearch.checkpoint.comJan 9, 2018, 7:22 AM - Apple Adds Spectre Protections to Safari, WebKitSecurityWeek
Updates released by Apple on Monday for iOS, macOS and Safari should mitigate the effects of the vulnerabilities exploited by the recently disclosed attack method named Spectre.
newswww.securityweek.comJan 9, 2018, 6:09 AM Qualcomm has confirmed that some of its products are affected by the recently disclosed Spectre and Meltdown vulnerabilities , but the company says mitigations are being deployed.
newswww.securityweek.comJan 8, 2018, 8:36 AMCisco is going to release security patches for Meltdown and Spectre attacks, the company is currently investigating its entire products portfolio. Cisco published a security advisory on the CPU Side-Channel information disclosure vulnerabilities that are exploited in the Spectre and Meltdown attacks and announced it is going to release security updates to protect its customers. Switchzilla announced it […]
newssecurityaffairs.comJan 6, 2018, 11:18 AM- Intel releases patches to mitigate Meltdown and Spectre attacksSecurity Affairs
Meltdown and Spectre attacks – According to Intel, by the end of the next week, the company will have issued security patches for more than 90% of chips commercialized in the past 5 years. White hat hackers from Google Project Zero this week disclosed the details of Meltdown and Spectre attacks targeting CPUs from major manufacturers, […]
newssecurityaffairs.comJan 5, 2018, 2:45 PM Update: Please note, Microsoft has suspended Windows security updates related to this issue on systems with older AMD CPUs, after a documentation mix-up led to the systems being unable to boot after patches were applied. Support forum posts are centered mostly on older Sempron and Athlon chips, the largest thread on the issue has more […]
newswww.csoonline.comJan 4, 2018, 11:08 PMGet an overview of the Meltdown and Spectre vulnerabilities including a risk assessment and calls to action.
vendorunit42.paloaltonetworks.comJan 4, 2018, 9:25 PMIn the wake of yesterday’s news and speculation about a serious design flaw in Intel processors, the security researchers involved in discovering the issue and the companies affected have started releasing details about it and about their mitigation efforts. As it turns out, there are two separate attacks that can result in exploitation of different issues: Meltdown – exploits CVE-2017-5754, and can lead to rogue data cache load Spectre – exploits CVE-2017-5753 and CVE-2017-5715, and … More →
newswww.helpnetsecurity.comJan 4, 2018, 7:31 PM- Meltdown and Spectre attacks affect almost any processor, including Intel, ARM, AMD onesSecurity Affairs
The Meltdown and Spectre attacks could allow attackers to steal sensitive data which is currently processed on the computer. Almost every modern processor is vulnerable to the ‘memory leaking’ flaws, this has emerged from technical analysis triggered after the announcement of vulnerabilities in Intel Chips. White hackers from Google Project Zero have disclosed the vulnerabilities that potentially impact […]
newssecurityaffairs.comJan 4, 2018, 3:15 PM - Tech Giants Address Critical CPU VulnerabilitiesSecurityWeek
Several major tech companies have started releasing patches and mitigations for the recently disclosed Meltdown and Spectre vulnerabilities affecting CPUs from Intel, AMD and ARM.
newswww.securityweek.comJan 4, 2018, 1:21 PM Details of “Meltdown” and “Spectre” Attacks Against Intel and AMD Chips Disclosed
newswww.securityweek.comJan 3, 2018, 10:20 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2018-9056CVSS 5.6 · Medium
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on th…
- CVE-2018-3693CVSS 5.6 · Medium
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a spe…
4 mentions - CVE-2017-5753CVSS 5.6 · Medium
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a sid…
- CVE-2017-5715CVSS 5.6 · Medium
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access…
- CVE-2018-3640CVSS 5.6 · Medium
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an at…
- CVE-2018-3639CVSS 5.5 · Medium
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthor…