CVE detail
CVE-2019-1125
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- August 2019 Patch Tuesday forecast: Expect updates from Adobe, stay current on other updatesHelp Net Security
Microsoft released details on August 6 regarding another variant of the Spectre Variant 1 speculative execution side channel vulnerability (CVE-2019-1125). The vulnerability was actually patched in the July 9 update for all currently supported Microsoft Windows operating systems, so if you are caught up on your OS security updates you are already covered. Unlike many of the Spectre and Meltdown vulnerabilities, this one did not require microcode updates from the device OEM. Also, the mitigation … More →
newswww.helpnetsecurity.comAug 9, 2019, 5:45 AM Security researchers have found a new way to abuse the speculative execution mechanism of modern CPUs to break security boundaries and leak the contents of kernel memory. The new technique abuses a system instruction called SWAPGS and can bypass mitigations put in place for previous speculative execution vulnerabilities like Spectre. The vulnerability was discovered by […]
newswww.csoonline.comAug 7, 2019, 10:13 AMResearchers have discovered yet another speculative execution vulnerability that can allow attackers to steal potentially sensitive information from devices with Intel processors.
newswww.securityweek.comAug 7, 2019, 10:02 AM- SWAPGS Attack – A new Spectre-V1 attack affects modern chipsSecurity Affairs
Experts discovered a new variant of the Spectre vulnerability (SWAPGS Attack) that affects modern Intel CPUs which leverage speculative-execution, and also some AMD processors. Experts discovered a new Spectre speculative execution flaw (SWAPGS attack), tracked as CVE-2019-1125, that affects all Modern Intel CPUs and some AMD processors. The flaw could be exploited by unprivileged local attackers to access […]
newssecurityaffairs.comAug 7, 2019, 7:07 AM - SWAPGS Attack: A new Spectre haunts machines with Intel CPUsHelp Net Security
Bitdefender researchers have uncovered yet another viable speculative execution side-channel attack that can be leveraged against Intel CPUs and the computers running on them. The SWAPGS Attack, as they call it, circumvents the protective measures that have been put in-place in response to earlier attacks such as Spectre and Meltdown. Still, there is plenty of good news: Microsoft has already released Windows patches for the flaw that makes the attack possible and, even though feasible, … More →
newswww.helpnetsecurity.comAug 6, 2019, 11:10 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2018-5391CVSS 7.5 · High
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause…
- CVE-2019-0820CVSS 7.5 · High
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. Th…
- CVE-2023-21776CVSS 5.5 · Medium
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-21765CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2023-21760CVSS 7.1 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2023-21757CVSS 7.5 · High
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability