CVE-2018-3620

intel core_i3: Sicherheitsluecke

mediumEPSS 5.6%

Description

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

intelcore_i3
intelcore_i5
intelcore_i7
intelcore_m
intelcore_m3
intelcore_m5
intelcore_m7
intelxeon

Metrics

5.6
Source: nvd-v3
92.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
no public PoC known
5.6 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2018-08-14 19:00 UTC

References & sources

Linked advisories