CVE-2017-5753
published 2018-01-04CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local…
PriorityP264medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EXPLOIT
EPSS
93.84%
99.8th percentile
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Affected
931 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | macos_high_sierra_10.13.2_supplemental_update | — | — |
| apple | safari | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.15.11-1 (bookworm) | linux 4.15.11-1 (bookworm) |
| debian | nvidia-graphics-drivers | < linux 4.15.11-1 (bookworm) | linux 4.15.11-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < linux 4.15.11-1 (bookworm) | linux 4.15.11-1 (bookworm) |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
| intel | atom_c | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Spectre variant 1 (CVE-2017-5753) exploits speculative execution and branch prediction to leak data from other processes; detection should focus on side-channel timing anomalies in user-space processes attempting to read cross-process or kernel memory ↗
- →Monitor for processes attempting to access memory contents of other processes, including kernel memory, as an indicator of Spectre exploitation attempts ↗
- ·Intel firmware updates for Broadwell and Haswell CPUs were pulled due to causing unexpected reboots and data loss/corruption; deploying these specific microcode patches may destabilize systems ↗
- ·Qualys virtual scanner appliances can be indirectly affected by Spectre/Meltdown if the vulnerability is exploitable at the hypervisor level; underlying hypervisors must be patched separately ↗
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv5.6MEDIUM
vendor_cisco5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USNS 3541-1 and 3523-1 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures in Ubuntu 17.10. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdown. A local attacker could
use this to expose sensitive information, including kernel memory.
(CVE-2017-5754)
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3597-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
USNS 3541-2 and 3523-2 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures for Ubuntu 16.04 LTS. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-02-22·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with Intel and AMD to provide
future microcode updates that implement IBRS and IBPB as they are made
a
Ubuntu
Linux kernel (KVM) vulnerabilities
vendor_ubuntu·2018-01-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (KVM) vulnerabilities
Title: Linux kernel (KVM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. (CVE-2017-5715, CVE-2017-5753)
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with Intel and AMD to provide
future microcode updates that imple
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Spectre. A local attacker
could use this to expose sensitive information, including kernel
memory. This update provides mitigations for the i386 (CVE-2017-5753
only) and amd64 architectures.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires corresponding processor microcode/firmware updates or,
in virtual environments, hypervisor updates. On i386 and amd64
architectures, the IBRS and IBPB features are required to enable the
kernel mitigations. Ubuntu is working with I
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3542-1 addressed vulnerabilities in the Linux kernel for Ubuntu
14.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for
Ubuntu 12.04 ESM.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Spectre. A local attacker
could use this to expose sensitive information, including kernel
memory. This update provides mitigations for the i386 (CVE-2017-5753
only) and amd64 architectures.
Instructions: Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)
requires
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3540-1 addressed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-2 mitigated CVE-2017-5754 (Meltdow
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 17.10. This update provides the corresponding
mitigations for the ppc64el architecture. Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative
execution a
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
USN-3541-1 addressed vulnerabilities in the Linux kernel for Ubuntu
17.10. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu
16.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-2 mitigated CVE-2017-5754 (Meltdown) for the amd6
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-01-23·CVSS 5.6
CVE-2017-5715 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were addressed in the Linux kernel.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 16.04 LTS. This update provides the
corresponding mitigations for the ppc64el architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative
executi
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2018-01-11·CVSS 5.6
CVE-2017-5715 [MEDIUM] WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: WebKitGTK+ could be made to expose sensitive information.
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5753, CVE-2017-5715)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Ubuntu
NVIDIA graphics drivers vulnerability
vendor_ubuntu·2018-01-09
CVE-2017-5753 NVIDIA graphics drivers vulnerability
Title: NVIDIA graphics drivers vulnerability
Summary: The system could be made to expose sensitive information.
Jann Horn discovered that microprocessors utilizing speculative execution
and branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Spectre. A local attacker could use this to
expose sensitive information, including kernel memory.
This update provides mitigations to address the issue, along with
compatibility fixes for the corresponding Linux kernel updates.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Apple
CVE-2017-5753: Safari 11.0.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5753
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: iOS 11.2.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5715
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: macOS High Sierra 10.13.2 Supplemental Update
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: macOS High Sierra 10.13.2 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13.2 Supplemental Update
Product: macOS High Sierra 10.13.2 Supplemental Update
CVE: CVE-2017-5715
Component: About Apple security updates
Description: macOS High Sierra 10.13.2 Supplemental Update includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5753: macOS High Sierra 10.13.2 Supplemental Update
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: macOS High Sierra 10.13.2 Supplemental Update
Apple Security Update: About the security content of macOS High Sierra 10.13.2 Supplemental Update
Product: macOS High Sierra 10.13.2 Supplemental Update
CVE: CVE-2017-5753
Component: About Apple security updates
Description: macOS High Sierra 10.13.2 Supplemental Update includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5753: iOS 11.2.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5753
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Apple
CVE-2017-5715: Safari 11.0.2
vendor_apple·2018-01-08·CVSS 5.6
CVE-2017-5715 [MEDIUM] CVE-2017-5715: Safari 11.0.2
Apple Security Update: About the security content of Safari 11.0.2
Product: Safari
Version: 11.0.2
CVE: CVE-2017-5715
Component: Safari 11.0.2
Description: Safari 11.0.2 includes security improvements to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to expose sensitive information.
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, CVE-2017-5754).
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Palo Alto
PAN-SA-2018-0001 Information about Meltdown and Spectre findings
vendor_paloalto·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-200 PAN-SA-2018-0001 Information about Meltdown and Spectre findings
PAN-SA-2018-0001 Information about Meltdown and Spectre findings
Palo Alto Networks is aware of recent vulnerability disclosures, known as Meltdown and Spectre, that affect modern CPU architectures. At this time, our findings show that these vulnerabilities pose no increased risk to Palo Alto Networks PAN-OS devices. (CVE-2017-5715, CVE-2017-5753, and CVE-2017-5754). This security advisory will be updated as more information becomes available or if there are changes in the impact of these vulnerabilities. PAN-OS/Panorama platforms are not directly impacted by these vulnerabilities, as successful
CVEs: CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Affected products: PAN-OS, Panorama
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] CWE-200 CPU Side-Channel Information Disclosure Vulnerabilities
CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel.
The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre. The third vulnerability, CVE-2017-5754, is known as Meltdown. The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
To exploit any
Red Hat
hw: cpu: speculative execution bounds-check bypass
vendor_redhat·2018-01-03·CVSS 5.6
CVE-2017-5753 [MEDIUM] CWE-226 hw: cpu: speculative execution bounds-check bypass
hw: cpu: speculative execution bounds-check bypass
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5753 triggers the speculative execution by performing a bounds-check bypass. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into th
VMware
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
vendor_vmware·2018-01-03·CVSS 5.6
CVE-2017-5715 [MEDIUM] VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
VMSA-2018-0002: VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution.
VMware ESXi, Workstation and Fusion updates address side-channel analysis due to speculative execution. Note: This document will focus on the Hypervisor-Specific Mitigations for the known variants of CVE-2017-5753 and CVE-2017-5715. Please review KB52245 for a holistic view on VMware’s response. 2. Relevant Products VMware vSphere ESXi (ESXi) VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description Bounds-Check bypass and Branch Target Injection issues CPU data cache timing can be abused to efficiently leak information out of mis-speculated CPU execution, leading to (at worst) arbitrary virtual memory read vulnerabilities a
Debian
CVE-2017-5753: linux - Systems with microprocessors utilizing speculative execution and branch predicti...
vendor_debian·2017·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: linux - Systems with microprocessors utilizing speculative execution and branch predicti...
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 4.15.11-1)
bullseye: resolved (fixed in 4.15.11-1)
forky: resolved (fixed in 4.15.11-1)
sid: resolved (fixed in 4.15.11-1)
trixie: resolved (fixed in 4.15.11-1)
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5715 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5715: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5753 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5753: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
Cisco
CPU Side-Channel Information Disclosure Vulnerabilities
vendor_cisco
CVE-2017-5754 CPU Side-Channel Information Disclosure Vulnerabilities
CVE-2017-5754: CPU Side-Channel Information Disclosure Vulnerabilities
On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to the operating system kernel. The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715, are collectively known as Spectre . The third vulnerability, CVE-2017-5754, is known as Meltdown . The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.
Kernel
platform/x86/amd/hsmp: Clamp ioctl/send_message indices (Spectre v1)
kernel_security·2026-06-12·CVSS 5.6
CVE-2017-5753 [MEDIUM] platform/x86/amd/hsmp: Clamp ioctl/send_message indices (Spectre v1)
platform/x86/amd/hsmp: Clamp ioctl/send_message indices (Spectre v1)
Although validate_message() checks msg_id, a mispredicted branch can
still allow speculative indexing into hsmp_msg_desc_table[]. Clamp
msg.msg_id with array_index_nospec() at entry to hsmp_ioctl_msg() so
downstream dereferences (including via is_get_msg() and
hsmp_send_message()) see a bounded index.
Similarly, hsmp_send_message() bounds-checks msg->sock_ind before
indexing hsmp_pdev.sock[], but a mispredicted branch can still
speculatively use the raw index (Spectre v1, CVE-2017-5753). Apply
array_index_nospec() after the check so every caller that reaches
hsmp_pdev.sock[] through this helper sees a clamped socket
index—including hsmp_ioctl_msg() and any other path that hands a
user-derived struct hsmp_message to hsmp
VulDB
Oracle Solaris 10/11.3 Kernel information disclosure (VU#584653 / EDB-43427)
vuldb·2026-05-29·CVSS 5.6
CVE-2017-5753 [MEDIUM] Oracle Solaris 10/11.3 Kernel information disclosure (VU#584653 / EDB-43427)
A vulnerability classified as critical was found in Oracle Solaris 10/11.3. The impacted element is an unknown function of the component Kernel. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2017-5753. The attack needs to be performed locally. Additionally, an exploit exists.
Upgrading the affected component is advised.
VulDB
Oracle Communications LSMS 13.1/13.2/13.3 Kernel information disclosure (VU#584653 / EDB-43427)
vuldb·2026-05-29·CVSS 5.6
CVE-2017-5753 [MEDIUM] Oracle Communications LSMS 13.1/13.2/13.3 Kernel information disclosure (VU#584653 / EDB-43427)
A vulnerability identified as critical has been detected in Oracle Communications LSMS 13.1/13.2/13.3. The affected element is an unknown function of the component Kernel. This manipulation causes information disclosure.
This vulnerability appears as CVE-2017-5753. The attack requires local access. In addition, an exploit is available.
You should upgrade the affected component.
VulDB
CPU on Intel/AMD/ARM Speculative Execution Spectre information disclosure (RHSA-2018:0292 / VU#584653)
vuldb·2026-05-29·CVSS 5.6
CVE-2017-5753 [MEDIUM] CPU on Intel/AMD/ARM Speculative Execution Spectre information disclosure (RHSA-2018:0292 / VU#584653)
A vulnerability marked as critical has been reported in CPU on Intel/AMD/ARM. Impacted is an unknown function of the component Speculative Execution. This manipulation causes information disclosure (Spectre).
This vulnerability is registered as CVE-2017-5753. Remote exploitation of the attack is possible. Furthermore, an exploit is available. This vulnerability is historically significant due to its background and the way it was received.
It is suggested to update the configuration settings.
OSV
linux-hwe vulnerabilities
osv·2018-03-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-3597-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu 16.04 LTS.
USNS 3541-2 and 3523-2 provided mitigations for Spectre and Meltdown
(CVE-2017-5715, CVE-2017-5753, CVE-2017-5754) for the i386, amd64,
and ppc64el architectures for Ubuntu 16.04 LTS. This update provides
the corresponding mitigations for the arm64 architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Meltdown. A local attacker could
use this to expose sensitive information, including ker
OSV
linux-kvm vulnerabilities
osv·2018-01-29·CVSS 5.6
CVE-2017-5715 [MEDIUM] linux-kvm vulnerabilities
linux-kvm vulnerabilities
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. (CVE-2017-5715, CVE-2017-5753)
OSV
linux, linux-aws, linux-euclid vulnerabilities
osv·2018-01-23·CVSS 5.6
CVE-2017-5753 [MEDIUM] linux, linux-aws, linux-euclid vulnerabilities
linux, linux-aws, linux-euclid vulnerabilities
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-1 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in Ubuntu 16.04 LTS. This update provides the
corresponding mitigations for the ppc64el architecture. Original
advisory details:
Jann Horn discovered that microprocessors utilizing speculative
execution and indirect branch prediction may allow unauthorized me
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-01-23·CVSS 5.6
[MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3540-1 addressed vulnerabilities in the Linux kernel for Ubuntu
16.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for
Ubuntu 14.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3522-2 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in the Linux Hardware Enablement (HWE) kernel
OSV
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
osv·2018-01-23·CVSS 5.6
[MEDIUM] linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-oem vulnerabilities
USN-3541-1 addressed vulnerabilities in the Linux kernel for Ubuntu
17.10. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 17.10 for Ubuntu
16.04 LTS.
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory
reads via sidechannel attacks. This flaw is known as Spectre. A
local attacker could use this to expose sensitive information,
including kernel memory. This update provides mitigations for the
i386 (CVE-2017-5753 only), amd64, ppc64el, and s390x architectures.
(CVE-2017-5715, CVE-2017-5753)
USN-3523-2 mitigated CVE-2017-5754 (Meltdown) for the amd64
architecture in the Linux Hardware Enablement (HW
OSV
linux vulnerabilities
osv·2018-01-23·CVSS 5.6
CVE-2017-5753 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jann Horn discovered that microprocessors utilizing speculative
execution and branch prediction may allow unauthorized memory reads via
sidechannel attacks. This flaw is known as Spectre. A local attacker
could use this to expose sensitive information, including kernel
memory. This update provides mitigations for the i386 (CVE-2017-5753
only) and amd64 architectures.
Kernel
Merge branch 'kvm-insert-lfence'
kernel_security·2018-01-16·CVSS 5.6
CVE-2017-5753 [MEDIUM] Merge branch 'kvm-insert-lfence'
Merge branch 'kvm-insert-lfence'
Topic branch for CVE-2017-5753, avoiding conflicts in the next merge window.
Kernel
KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
kernel_security·2018-01-15·CVSS 5.6
CVE-2017-5715 [MEDIUM] KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
KVM: PPC: Book3S: Provide information about hardware/firmware CVE workarounds
This adds a new ioctl, KVM_PPC_GET_CPU_CHAR, that gives userspace
information about the underlying machine's level of vulnerability
to the recently announced vulnerabilities CVE-2017-5715,
CVE-2017-5753 and CVE-2017-5754, and whether the machine provides
instructions to assist software to work around the vulnerabilities.
The ioctl returns two u64 words describing characteristics of the
CPU and required software behaviour respectively, plus two mask
words which indicate which bits have been filled in by the kernel,
for extensibility. The bit definitions are the same as for the
new H_GET_CPU_CHARACTERISTICS hypercall.
There is also a new capability, KVM_CAP_PPC_GET_CPU_CHAR, which
indicates whether the new ioctl
Kernel
Merge branch 'kvm-insert-lfence' into kvm-master
kernel_security·2018-01-11·CVSS 5.6
CVE-2017-5753 [MEDIUM] Merge branch 'kvm-insert-lfence' into kvm-master
Merge branch 'kvm-insert-lfence' into kvm-master
Topic branch for CVE-2017-5753, avoiding conflicts in the next merge window.
OSV
webkit2gtk vulnerabilities
osv·2018-01-11·CVSS 5.6
CVE-2017-5753 [MEDIUM] webkit2gtk vulnerabilities
webkit2gtk vulnerabilities
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5753, CVE-2017-5715)
Kernel
KVM: x86: Add memory barrier on vmcs field lookup
kernel_security·2018-01-10·CVSS 5.6
CVE-2017-5753 [MEDIUM] KVM: x86: Add memory barrier on vmcs field lookup
KVM: x86: Add memory barrier on vmcs field lookup
This adds a memory barrier when performing a lookup into
the vmcs_field_to_offset_table. This is related to
CVE-2017-5753.
Signed-off-by: Andrew Honig
Reviewed-by: Jim Mattson
Cc: [email protected]
Signed-off-by: Paolo Bonzini
Kernel
bpf: prevent out-of-bounds speculation
kernel_security·2018-01-07·CVSS 5.6
CVE-2017-5753 [MEDIUM] bpf: prevent out-of-bounds speculation
bpf: prevent out-of-bounds speculation
Under speculation, CPUs may mis-predict branches in bounds checks. Thus,
memory accesses under a bounds check may be speculated even if the
bounds check fails, providing a primitive for building a side channel.
To avoid leaking kernel data round up array-based maps and mask the index
after bounds check, so speculated load with out of bounds index will load
either valid value from the array or zero from the padded area.
Unconditionally mask index for all array types even when max_entries
are not rounded to power of 2 for root user.
When map is created by unpriv user generate a sequence of bpf insns
that includes AND operation to make sure that JITed code includes
the same 'index & index_mask' operation.
If prog_array map is created by unpriv user r
OSV
firefox vulnerabilities
osv·2018-01-05·CVSS 5.6
CVE-2017-5715 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, CVE-2017-5754).
OSV
CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
osv·2018-01-04·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wit
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Kernel
kvm: vmx: Scrub hardware GPRs at VM-exit
kernel_security·2018-01-03
kvm: vmx: Scrub hardware GPRs at VM-exit
kvm: vmx: Scrub hardware GPRs at VM-exit
Guest GPR values are live in the hardware GPRs at VM-exit. Do not
leave any guest values in hardware GPRs after the guest GPR values are
saved to the vcpu_vmx structure.
This is a partial mitigation for CVE 2017-5715 and CVE 2017-5753.
Specifically, it defeats the Project Zero PoC for CVE 2017-5715.
Suggested-by: Eric Northup
Signed-off-by: Jim Mattson
Reviewed-by: Eric Northup
Reviewed-by: Benjamin Serebrin
Reviewed-by: Andrew Honig
[Paolo: Add AMD bits, Signed-off-by: Tom Lendacky ]
Signed-off-by: Paolo Bonzini
Project0
Reading privileged memory with a side-channel - Project Zero
project_zero·2018-01-01·CVSS 5.6
CVE-2017-5715 [MEDIUM] Reading privileged memory with a side-channel - Project Zero
Posted by Jann Horn, Project Zero
We have discovered that CPU data cache timing can be abused to efficiently leak information out of mis-speculated execution, leading to (at worst) arbitrary virtual memory read vulnerabilities across local security boundaries in various contexts.
Variants of this issue are known to affect many modern processors, including certain processors by Intel, AMD and ARM. For a few Intel and AMD CPU models, we have exploits that work against real software. We reported this issue to Intel, AMD and ARM on 2017-06-01 [1].
So far, there are three known variants of the issue:
-
Variant 1: bounds check bypass (CVE-2017-5753)
-
Variant 2: branch target injection (CVE-2017-5715)
-
Variant 3: rogue data cache load (CVE-2017-5754)
Before the issues described he
Suricata
ET EXPLOIT Possible Spectre PoC Download In Progress
suricata·2018-01-10
CVE-2017-5753 ET EXPLOIT Possible Spectre PoC Download In Progress
ET EXPLOIT Possible Spectre PoC Download In Progress
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Spectre PoC Download In Progress"; flow:established,to_client; flowbits:isset,ET.http.binary; file.data; content:"|E7 03 00 00|"; content:"|48 0F AE|"; distance:17; within:9; pcre:"/^[\x30-\x3f\x7D]/Rs"; content:"|48 0F AE 3D|"; distance:41; within:10; content:"|48 98|"; distance:64; within:22; content:"|0F 01 F9|"; distance:50; within:9; content:"|0F 01 F9|"; distance:30; within:9; reference:cve,2017-5753; reference:cve,2017-5715; classtype:attempted-admin; sid:2025196; rev:3; metadata:attack_target Client_Endpoint, created_at 2018_01_10, cve CVE_2017_5753, deployment Perimeter, malware_family Spectre_Exploit, performance_impact Low, confidence Medium, signat
Suricata
ET WEB_CLIENT Spectre Exploit Javascript
suricata·2018-01-09
CVE-2017-5753 ET WEB_CLIENT Spectre Exploit Javascript
ET WEB_CLIENT Spectre Exploit Javascript
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Spectre Exploit Javascript"; flow:established,to_client; file.data; content:"0x1000000"; fast_pattern; pcre:"/(?[^=\s]*)\s*=\s*0x1000000.+?\x28\s*\x28\s*\x28\s*\w+\s*<<\s*12\s*\x29\s*\|\s*0\s*\x29\s*\+\s*(?P=var1)\s*\x29\s*\|\s*0/s"; reference:cve,2017-5753; reference:cve,2017-5715; reference:url,github.com/cgvwzq/spectre; classtype:attempted-user; sid:2025188; rev:7; metadata:affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2018_01_09, cve CVE_2017_5753, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_14;)
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
Spectre and Meltdown
blogs_tenable·2022-11-07·CVSS 5.6
[MEDIUM] Spectre and Meltdown
by Carole Fennelly November 7, 2022
A compromised processor is one of the most serious attack vectors on any platform. The hardware bugs known as Spectre and Meltdown affect modern processors by accessing information found in the system's memory. The Spectre and Meltdown dashboard provides insight into which systems are affected by these hardware bugs.
The Spectre and Meltdown bugs use side channels to obtain information from the accessed memory location. Spectre allows an application to force another application to access arbitrary portions of its memory, which can then be read through a side channel. This unique side channel attack uses speculative execution, a technique used by high-speed processors, to increase performance by guessing likely future execution paths and preemptively ex
Tenable
Getting Started with Tenable.sc Using SLA's
blogs_tenable·2020-01-10
Getting Started with Tenable.sc Using SLA's
by Cody Dumont January 10, 2020
Service Level Agreements often change from one organizations to the next, however meeting SLA’s is a common issue among organizations industry wide. Tenable.sc provides a vast array of data that provides vulnerability management SLA metrics, but where can the CISO get started? This dashboard is commonly used by the sales team at Tenable to help coach organizations to meet SLA’s. The components in this dashboard are grouped in 3-series, which provide a CISO and Risk Manager with a starting point for SLA analysis.
The first few rows provide a detailed analysis on SLA’s for vulnerabilities based on Common Vulnerability Scoring System (CVSS) and Vulnerability Priority Rating (VPR). Traditionally many SLA’s are based on Microsoft’s Patch Tuesday and provide org
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution Q1 2018
blogs_securelist·2018-05-14
IT threat evolution Q1 2018
Authors
- David Emm
## Targeted attacks and malware campaigns
### Skygofree: sophisticated mobile surveillance
In January, we uncovered a sophisticated mobile implant that provides attackers with remote control of infected Android devices. The malware, called Skygofree (after one of the domains it uses), is a targeted cyber-surveillance tool that has been in development since 2014. The malware is spread by means of spoofed web pages that mimic leading mobile providers. The campaign is ongoing and our telemetry indicates that there have been several victims, all in Italy. We feel confident that the developer of Skygofree is an Italian IT company that works on surveillance solutions.
The latest version of Skygofree includes functionality that has so far not been seen in the wild. Featur
Securelist
IT threat evolution Q1 2018
blogs_securelist·2018-05-14
IT threat evolution Q1 2018
Authors
David Emm
## Targeted attacks and malware campaigns
## Skygofree: sophisticated mobile surveillance
In January, we uncovered a sophisticated mobile implant that provides attackers with remote control of infected Android devices. The malware, called Skygofree (after one of the domains it uses), is a targeted cyber-surveillance tool that has been in development since 2014. The malware is spread by means of spoofed web pages that mimic leading mobile providers. The campaign is ongoing and our telemetry indicates that there have been several victims, all in Italy. We feel confident that the developer of Skygofree is an Italian IT company that works on surveillance solutions.
The latest version of Skygofree includes functionality that has so far not been seen in the wild. Features
Qualys
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack
blogs_qualys·2018-03-02
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack
Apple has been all over InfoSec news in the past week or so, along with Spectre / Meltdown developments, a tax season scam alert from the feds, and an apparent solution to the Winter Olympics’ hack whodunit. In addition, researchers warned about a new trend of using Memcached servers to significantly boost DDoS attacks, as GitHub became a victim of this new tactic.
## Apple under siege
The second half of February was intense for Apple on the security front. A digital forensics vendor claimed having the ability to unlock all iPhone models, including the X, while a researcher warned about a Trojan targeting MacOs computers that’s not detected by anti-virus products. Oh, and Apple had to squash another one of those pesky bugs that let people crash iPhones via texting.
Unlocking iPhones
Fo
Qualys
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack | Qualys
blogs_qualys·2018-03-02
Apple in the InfoSec Spotlight, as GitHub Falls Prey to Amplified DDoS Attack | Qualys
Apple has been all over InfoSec news in the past week or so, along with Spectre / Meltdown developments, a tax season scam alert from the feds, and an apparent solution to the Winter Olympics’ hack whodunit. In addition, researchers warned about a new trend of using Memcached servers to significantly boost DDoS attacks, as GitHub became a victim of this new tactic.
### Apple under siege
A digital forensics vendor claims it can crack iOS devices, including the iPhone X, pictured here. (Photo credit: Apple)
The second half of February was intense for Apple on the security front. A digital forensics vendor claimed having the ability to unlock all iPhone models, including the X, while a researcher warned about a Trojan targeting MacOs computers that’s not detected by anti-virus products. Oh
Qualys
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
blogs_qualys·2018-02-16
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
### Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Qualys
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
blogs_qualys·2018-02-16
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
## Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
## Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some progr
Qualys
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
blogs_qualys·2018-02-09
Intel Makes Spectre Patch Progress, while Adobe Grapples with Latest Flash Bug | Qualys
It’s been a busy week in InfoSec land, as Intel released a new Spectre patch, iOS source code was leaked online, and a zero-day Flash bug got exploited in the wild.
Also making noise these past few days: A major security hole in the Grammarly web app, WordPress updates tripping over each other, and a data breach at a Swiss telecom company.
As has been the case these past few weeks, we’ll lead off with the latest on Meltdown and Spectre, the hardware vulnerabilities whose disclosure on Jan. 3 sent shockwaves through the IT industry due to their scope and severity, and which are expected to remain an issue for years.
### Intel mitigates Spectre vulnerability with Skylake update
For a change, the latest Meltdown / Spectre development is encouraging: On Wednesday, Intel announced some prog
Qualys
Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits
blogs_qualys·2018-02-02·CVSS 5.6
[MEDIUM] Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits
This week brought new developments in the Meltdown / Spectre saga, including more concerns about Intel’s buggy patches, and mounting evidence that hackers are trying to create exploits for the vulnerabilities.
It seemed that after weeks of complaints and confusion , Intel’s issue had hit bottom and was headed for a resolution on Monday of last week. That’s when the company said its firmware updates for Broadwell and Haswell CPUs shouldn’t be installed anymore , because, as many customers had reported, they made systems behave erratically, including unexpectedly rebooting.
At the time, Intel said it had discovered the “root cause” for the firmware’s problems, and was already actively developing new updates. However, another shoe was about to drop. Three days later Intel acknowledged in it
Qualys
Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits | Qualys
blogs_qualys·2018-02-02·CVSS 5.6
[MEDIUM] Meltdown / Spectre: New Concerns Over Intel Patches, as Hackers Test Exploits | Qualys
This week brought new developments in the Meltdown / Spectre saga, including more concerns about Intel’s buggy patches, and mounting evidence that hackers are trying to create exploits for the vulnerabilities.
It seemed that after weeks of complaints and confusion, Intel’s issue had hit bottom and was headed for a resolution on Monday of last week. That’s when the company said its firmware updates for Broadwell and Haswell CPUs shouldn’t be installed anymore, because, as many customers had reported, they made systems behave erratically, including unexpectedly rebooting.
At the time, Intel said it had discovered the “root cause” for the firmware’s problems, and was already actively developing new updates. However, another shoe was about to drop. Three days later Intel acknowledged in its
Fortinet
Meltdown/Spectre Update
blogs_fortinet·2018-01-30·CVSS 5.6
CVE-2017-5715 [MEDIUM] Meltdown/Spectre Update
FORTIGUARD LABS THREAT RESEARCH
Meltdown/Spectre Update
By FortiGuard SE Team | January 30, 2018
Earlier this month, three major chip manufacturers announced that vulnerabilities known as Meltdown and Spectre (CVE-2017-5715, CVE-2017-5753 and CVE-2017-5754) affected processors deployed in millions of devices.
For the past year or so, FortiGuard Labs has been tracking the efforts of cybercriminals to develop new attacks designed to exploit known vulnerabilities. As detailed in our Fortinet Threat Report for Q2 of 2017, a full 90% of organizations recorded exploits for vulnerabilities that were three or more years old. Even 10+ years after a flaw’s release, 60% of firms still see related attacks.
The rate at which the cybercriminal community is targeting known vulnerabilities is clearly
Qualys
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout
blogs_qualys·2018-01-26
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout
IT departments and tech vendors continued grappling with Spectre and Meltdown this week, as Intel pulled its glitchy patches and the U.S. Congress questioned the vulnerability disclosures’ timing and scope.
Spectre and Meltdown aren’t typical vulnerabilities for a number of reasons, and as a result, they’ve proven problematic to deal with. Intel, whose products are the most impacted, has had a particularly rocky time crafting its firmware updates for mitigating the bugs.
After receiving multiple complaints from customers, in particular data center operators, that the firmware updates for Broadwell and Haswell CPUs were causing systems to unexpectedly reboot, Intel on Monday finally deep-sixed them .
“We recommend that OEMs, cloud service providers, system manufacturers, software vendors
Qualys
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout | Qualys
blogs_qualys·2018-01-26
Meltdown/Spectre: Intel Nixes Patches, Tech CEOs Questioned on Information Blackout | Qualys
IT departments and tech vendors continued grappling with Spectre and Meltdown this week, as Intel pulled its glitchy patches and the U.S. Congress questioned the vulnerability disclosures’ timing and scope.
Spectre and Meltdown aren’t typical vulnerabilities for a number of reasons, and as a result, they’ve proven problematic to deal with. Intel, whose products are the most impacted, has had a particularly rocky time crafting its firmware updates for mitigating the bugs.
After receiving multiple complaints from customers, in particular data center operators, that the firmware updates for Broadwell and Haswell CPUs were causing systems to unexpectedly reboot, Intel on Monday finally deep-sixed them.
“We recommend that OEMs, cloud service providers, system manufacturers, software vendors
Qualys
Meltdown and Spectre Aren’t Business as Usual | Qualys
blogs_qualys·2018-01-18·CVSS 5.6
[MEDIUM] Meltdown and Spectre Aren’t Business as Usual | Qualys
The new year brought a new vulnerability type — the CPU-based Meltdown and Spectre bugs — that’s forcing vendors and IT departments to modify long-standing ways of identifying threats, prioritizing remediation, managing patches and evaluating risk.
“Meltdown and Spectre are different vulnerabilities from what you’re used to seeing,” Jimmy Graham, a Product Management Director at Qualys, said during a webcast on Wednesday.
As a result, it’s essential for organizations to fully understand the nature of these vulnerabilities, stay on top of the latest information, and analyze the vulnerabilities’ impact in their IT environments, in order to stay as safe as possible.
“It’s not a simple [process] of just install a patch and you’re done,” he said.
### A different animal
Graham outlined a nu
Qualys
Meltdown and Spectre Aren’t Business as Usual
blogs_qualys·2018-01-18·CVSS 5.6
[MEDIUM] Meltdown and Spectre Aren’t Business as Usual
The new year brought a new vulnerability type — the CPU-based Meltdown and Spectre bugs — that’s forcing vendors and IT departments to modify long-standing ways of identifying threats, prioritizing remediation, managing patches and evaluating risk.
“Meltdown and Spectre are different vulnerabilities from what you’re used to seeing,” Jimmy Graham, a Product Management Director at Qualys, said during a webcast on Wednesday.
As a result, it’s essential for organizations to fully understand the nature of these vulnerabilities, stay on top of the latest information, and analyze the vulnerabilities’ impact in their IT environments, in order to stay as safe as possible.
“It’s not a simple [process] of just install a patch and you’re done,” he said.
## A different animal
Graham outlined a num
Fortinet
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
blogs_fortinet·2018-01-12
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
FORTIGUARD LABS THREAT RESEARCH
Dr. StrangePatch or: How I Learned to Stop Worrying (about Meltdown and Spectre) and Love Security Advisory ADV180002
By Minh Tran | January 12, 2018
Introduction
2018 truly is starting off with a bang: fundamental CPU flaws dubbed Meltdown and Spectre were found affecting pretty much all modern processors developed since the Pentium Pro (1995). These flaws root in two critical CPU features: Out of Order Execution and Speculative Execution, which are crucial for performance. Since this is an important feature and not a bug, it is inherently hard to fix. Furthermore, for performance reasons, speculative execution is almost always implemented in hardware, so “fixes” tend toward mitigations (e.g. microcode updates).
Due to the serious nature of these flaws,
Qualys
Meltdown/Spectre and Qualys Cloud Platform | Qualys
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] Meltdown/Spectre and Qualys Cloud Platform | Qualys
In light of the recently released information about two security vulnerabilities, Qualys has considered the impact on the Qualys Cloud Platform and associated services. Qualys released a detailed advisory for customers of the Qualys Cloud Platform to help customers identify these vulnerabilities and to assist customers in their internal security assessment.
Below, please find information about how Qualys has performed its assessment and is taking steps to protect its environment and the Qualys Cloud Platform:
### About Meltdown and Spectre
Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5715 and CVE-2017-5753) exploit physical implementations of modern microprocessors, rather than relying on any software-based flaw or defect.
### Impact
As of this writing, there is no known exploit for
Qualys
Meltdown/Spectre and Qualys Cloud Platform
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] Meltdown/Spectre and Qualys Cloud Platform
In light of the recently released information about two security vulnerabilities, Qualys has considered the impact on the Qualys Cloud Platform and associated services. Qualys released a detailed advisory for customers of the Qualys Cloud Platform to help customers identify these vulnerabilities and to assist customers in their internal security assessment.
Below, please find information about how Qualys has performed its assessment and is taking steps to protect its environment and the Qualys Cloud Platform:
## About Meltdown and Spectre
Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5715 and CVE-2017-5753) exploit physical implementations of modern microprocessors, rather than relying on any software-based flaw or defect.
## Impact
As of this writing, there is no known exploit for t
Qualys
January 2018 Patch Tuesday - Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch | Qualys
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] January 2018 Patch Tuesday - Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch | Qualys
Due to the disclosure of Meltdown and Spectre, Microsoft released several patches last week with the ranking “Important.” While there are no active attacks against these vulnerabilities, a special focus should be placed on any of the browser patches, due to potential attacks using JavaScript.
It is important to note that OS-level and BIOS (microcode) patches that are designed to mitigate Meltdown and Spectre may lead to performance issues. It is important to test all patches before deploying.
Some of these updates are incompatible with third-party antivirus software, and may require updating AV on workstations and servers. Microsoft has released guidance documents for both Windows clients and servers. Windows Server requires registry changes in order to implement the protections added by
Qualys
January 2018 Patch Tuesday – Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch
blogs_qualys·2018-01-09·CVSS 5.6
[MEDIUM] January 2018 Patch Tuesday – Meltdown/Spectre, 16 Critical Microsoft Patches, 1 Adobe Patch
Due to the disclosure of Meltdown and Spectre , Microsoft released several patches last week with the ranking “Important.” While there are no active attacks against these vulnerabilities, a special focus should be placed on any of the browser patches, due to potential attacks using JavaScript.
It is important to note that OS-level and BIOS (microcode) patches that are designed to mitigate Meltdown and Spectre may lead to performance issues. It is important to test all patches before deploying.
Some of these updates are incompatible with third-party antivirus software, and may require updating AV on workstations and servers. Microsoft has released guidance documents for both Windows clients and servers . Windows Server requires registry changes in order to implement the protections added
Talos
Meltdown and Spectre
blogs_talos·2018-01-08·CVSS 5.6
[MEDIUM] Meltdown and Spectre
## Meltdown and Spectre
Cisco Talos is aware of three new vulnerabilities impacting Intel, AMD, Qualcomm and ARM processors used by almost all computers. We are investigating these issues and although we have not observed exploitation of these vulnerabilities in the wild, that does not mean that it has not occurred. We have observed publicly available proof of concept exploit code being developed to exploit these vulnerabilities.
These issues have been assigned the following CVE entries:
Meltdown: An attacker can access kernel memory from user space
Rogue data cache load ( CVE-2017-5754 ) Spectre: An attacker can read memory contents from other users' running programs
Branch target injection ( CVE-2017-5715 )
Bounds check bypass ( CVE-2017-5753 ) These issues involve side channel and
Talos
Meltdown and Spectre
blogs_talos·2018-01-08·CVSS 5.6
[MEDIUM] Meltdown and Spectre
Cisco Talos is aware of three new vulnerabilities impacting Intel, AMD, Qualcomm and ARM processors used by almost all computers. We are investigating these issues and although we have not observed exploitation of these vulnerabilities in the wild, that does not mean that it has not occurred. We have observed publicly available proof of concept exploit code being developed to exploit these vulnerabilities.
These issues have been assigned the following CVE entries:
Meltdown: An attacker can access kernel memory from user space
- Rogue data cache load (CVE-2017-5754) Spectre: An attacker can read memory contents from other users' running programs
- Branch target injection (CVE-2017-5715)
- Bounds check bypass (CVE-2017-5753)
These issues involve side channel and cache attacks that enable
Trendmicro
Understanding Meltdown and Spectre
blogs_trendmicro·2018-01-05
Understanding Meltdown and Spectre
Exploits & Vulnerabilities
# Understanding Meltdown and Spectre
After the official disclosure of the Meltdown and Spectre vulnerabilities, it became clear how serious the problems were. In short, Meltdown and Spectre both allow malicious code to read memory that they would normally not have permission to.
By: Vit Sembera
2018/01/05
Read time: ( words)
Save to Folio
For several days, rumors circulated about a serious vulnerability in Intel processors. It wasn’t until January 3 that the official disclosure of the Meltdown and Spectre vulnerabilities was made, and it became clear how serious the problems were. To summarize, Meltdown and Spectre both allow malicious code to read memory that they would normally not have permission to.
The vulnerability can allow an attacker to steal info
Zscaler
Meltdown, Spectre, CPU Side-Channel Attack | Zscaler Blog
blogs_zscaler·2018-01-05
Meltdown, Spectre, CPU Side-Channel Attack | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
blogs_tenable·2018-01-04
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Processor Vulnerabilities – Meltdown and Spectre
blogs_qualys·2018-01-04·CVSS 5.6
CVE-2017-5754 [MEDIUM] Processor Vulnerabilities – Meltdown and Spectre
UPDATE 1/4/2018: Qualys has released several QIDs for detecting missing patches for these vulnerabilities.
UPDATE 1/5/2018: Pre-built AssetView dashboards to visualize impact and remediation progress.
Vulnerabilities potentially impacting all major processor vendors were disclosed today by Google Project Zero. These vulnerabilities have been named Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 & CVE-2017-5715). Organizations should inventory their systems by processor type, apply vendor patches as they become available, and track their progress. This article describes how Qualys can help in all three areas.
## Overview
Meltdown allows any application to access all system memory, including memory allocated for the kernel. Mitigation for this vulnerability will require operating syst
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
blogs_sentinelone·2018-01-04·CVSS 5.6
CVE-2017-5753 [MEDIUM] SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
This document covers SentinelOne’s response to exploit flaws described in CVE-2017-5753, CVE-2017-5715, and CVE-2017-5754.
SentinelOne products are compatible with Microsoft’s January 3, 2018, security updates. We tested our Agent against Microsoft’s patch. No incompatibilities causing any stop errors or other issues were found with SentinelOne agent versions 1.8.4, 2.0, 2.1 and 2.5.
## Overview
Microsoft, Google, Linux RedHat and Amazon have all acknowledged a new, publicly disclosed class of vulnerabilities referred to as “speculative execution side-channel attacks,” which affect many modern processors and operating systems including Intel, AMD, and ARM. This issue may also affect other systems, such as Android, Chrome, iOS, MacOS.
## Possible collision with security applications
Mi
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
blogs_sentinelone·2018-01-04·CVSS 5.6
CVE-2017-5753 [MEDIUM] SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes
This document covers SentinelOne’s response to exploit flaws described in CVE-2017-5753 , CVE-2017-5715 , and CVE-2017-5754 .
SentinelOne products are compatible with Microsoft’s January 3, 2018, security updates. We tested our Agent against Microsoft’s patch. No incompatibilities causing any stop errors or other issues were found with SentinelOne agent versions 1.8.4, 2.0, 2.1 and 2.5.
## Overview
Microsoft , Google , Linux RedHat and Amazon have all acknowledged a new, publicly disclosed class of vulnerabilities referred to as “speculative execution side-channel attacks,” which affect many modern processors and operating systems including Intel, AMD, and ARM. This issue may also affect other systems, such as Android, Chrome, iOS, MacOS.
## Possible collision with security application
Unit42
Threat Brief: Meltdown and Spectre Vulnerabilities
blogs_unit42·2018-01-04·CVSS 5.6
[MEDIUM] Threat Brief: Meltdown and Spectre Vulnerabilities
Bottom line up front:
- The Meltdown and Spectre vulnerabilities are serious vulnerabilities
- These vulnerabilities are uniquely broad in scope potentially affecting nearly every computer and device with a modern processor: Microsoft Windows, Google Android, Google ChromeOS, Apple macOS, on Intel and ARM processors.
- These are not code execution vulnerabilities (i.e. wormable): they are information disclosure vulnerabilities
- These vulnerabilities pose greatest risk in shared hosting scenarios (i.e. cloud)
- The risk these vulnerabilities pose for end users is that malicious code or script could use them to obtain sensitive information like usernames, passwords, and bank account information
- Because of the breadth of these vulnerabilities, IoT devices and many mobile devices may never
Tenable
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
blogs_tenable·2018-01-04
The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
Blog / Research
Subscribe
# The First Major Security Logos of 2018: Spectre and Meltdown Vulnerabilities
Cody Dumont
January 4, 2018
6 Min Read
This post was updated on Jan. 12, 2018 to include additional technical details and supplemental links.
The recently disclosed Meltdown and Spectre vulnerabilities started off 2018 with a somber note, as the attacks affect everything from desktops, laptops and mobile devices to cloud providers’ infrastructure. The flaws are present in nearly all modern microprocessors and can allow an attacker to access privileged memory by abusing a feature called speculative execution.
### Speculative execution
Speculative execution is a technique that allows a microprocessor to increase performance by operating on multiple branches of instructions at once
Unit42
Threat Brief: Meltdown and Spectre Vulnerabilities
blogs_unit42·2018-01-04
Threat Brief: Meltdown and Spectre Vulnerabilities
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Meltdown and Spectre Vulnerabilities
Unit 42
Published: January 4, 2018
High Profile Threats
Vulnerabilities
AMD
Android
ARM
Intel
Linux
MacOS
Microsoft Windows
Bottom line up front:
The Meltdown and Spectre vulnerabilities are serious vulnerabilities
These vulnerabilities are uniquely broad in scope potentially affecting nearly every computer and device with a modern processor: Microsoft Windows, Google Android, Google ChromeOS, Apple macOS, on Intel and ARM processors.
These are not code execution vulnerabilities (i.e. wormable): they are information disclosure vulnerabilities
These vulnerabilities pose greatest risk in shared hosting scenarios (i.e. cloud)
The risk these vulnerabilities po
Fortinet
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
blogs_fortinet·2018-01-04·CVSS 5.6
[MEDIUM] Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
FORTINET NEWS & UPDATES
Fortinet Advisory on New Spectre and Meltdown Vulnerabilities
By Fortinet | January 04, 2018
Earlier this week, it was announced that researchers uncovered two new side channel attacks that exploit newly discovered vulnerabilities found in most CPU processors, including those from Intel, AMD, and ARM. These vulnerabilities allow malicious userspace processes to read kernel memory, thereby potentially causing sensitive kernel information to leak. These vulnerabilities are known as Meltdown and Spectre.
Fortinet’s PSIRT team is actively conducting an extensive review to determine the potential impact to Fortinet solutions, and at this time has classified the risk to Fortinet products as low. Meltdown and Spectre are "Information Disclosure" and "Privilege Escalatio
Qualys
Processor Vulnerabilities - Meltdown and Spectre | Qualys
blogs_qualys·2018-01-04·CVSS 5.6
CVE-2017-5754 [MEDIUM] Processor Vulnerabilities - Meltdown and Spectre | Qualys
UPDATE 1/4/2018: Qualys has released several QIDs for detecting missing patches for these vulnerabilities.
UPDATE 1/5/2018: Pre-built AssetView dashboards to visualize impact and remediation progress.
Vulnerabilities potentially impacting all major processor vendors were disclosed today by Google Project Zero. These vulnerabilities have been named Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 & CVE-2017-5715). Organizations should inventory their systems by processor type, apply vendor patches as they become available, and track their progress. This article describes how Qualys can help in all three areas.
### Overview
Meltdown allows any application to access all system memory, including memory allocated for the kernel. Mitigation for this vulnerability will require operating sy
Tenable
Spectre & Meltdown
blogs_tenable·2018-01-04
Spectre & Meltdown
by Steve Tilson January 4, 2018
A compromised processor is one of the most serious attack vectors on all Microsoft, Apple, and Linux systems. The recent discovered hardware bugs known as “Spectre & Meltdown” affect modern processors uniquely by accessing information found in the system’s memory. This Dashboard can provide insight to which systems are prone to the new vulnerability.
The new bugs are considered side channel attacks since they use side channels to obtain the information from the accessed memory location. Spectre allows an application to force another application to access arbitrary portions of its memory, which can then be read through a side channel. This unique side channel attack is done by speculative execution, a technique used by high-speed processors in order to incr
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
Crowdstrike
What are the Spectre & Meltdown Chip Flaws?
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] What are the Spectre & Meltdown Chip Flaws?
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Comparing Security and Efficiency of WebAssembly and Linux Containers in Kubernetes Cloud Computing
arxiv_fulltext·2024-11-02
Comparing Security and Efficiency of WebAssembly and Linux Containers in Kubernetes Cloud Computing
minipage
*Zusammenfassung
In dieser Studie wird das Potenzial von WebAssembly als sicherere und effizientere Alternative zu Linux-Containern für die Ausführung von nicht vertrauenswürdigem Code im Cloud-Computing mit Kubernetes untersucht.
Insbesondere werden die Auswirkungen dieses Wechsels auf Sicherheit und Leistung bewertet.
Sicherheitsanalysen zeigen, dass sowohl Linux-Container als auch WebAssembly bei der Ausführung von nicht vertrauenswürdigem Code Angriffsflächen bieten, wobei diese Angriffsfläche bei WebAssembly aufgrund einer zusätzlichen Isolierungsschicht geringer ausfällt.
Die Leistungsanalyse zeigt außerdem, dass WebAssembly ineffizientere Ausführung als nativer Code bedingt und hohe Kaltstartzeiten hat, die bei lang laufenden Berechnungen vernachlässigbar sein könnten.
We
arXiv
Fundamental Challenges in Cybersecurity and a Philosophy of Vulnerability-Guided Hardening
arxiv_fulltext·2024-09-03
Fundamental Challenges in Cybersecurity and a Philosophy of Vulnerability-Guided Hardening
Fundamental Challenges in Cybersecurity and\ Philosophy of Vulnerability-Guided Hardening
Marcel B\"ohme\ -SP, Germany-0.4cm
## Abstract
Research\,in\,cybersecurity\,may\,seem\,reactive,\,specific, ephemeral, and indeed ineffective. Despite decades of innovation in defense, even the most critical software systems turn out to be vulnerable to attacks. Time and again. Offense and defense forever on repeat. Even provable security, meant to provide an indubitable guarantee of security, does not stop attackers from finding security flaws. As we reflect on our achievements, we are left wondering: Can security be solved once and for all?
In this paper, we take a philosophical perspective and develop the first theory of cybersecurity that explains what fundamentally prevents us from making rel
arXiv
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
arxiv_fulltext·2024-06-09
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Aidan Z.H. Yang
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Haoye Tian
[email protected]
University of Melbourne
Melbourne
Australia
He Ye
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Ruben Martins
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Claire Le Goues
[email protected]
Carnegie Mellon University
Pittsburgh
United States
## Abstract
Software security vulnerabilities allow attackers to perform malicious activities to disrupt software operations. Recent Transformer-based language models have significantly advanced vulnerability detection, surpassing the capabilities of static analysis based deep lear
arXiv
ZeroLeak: Using LLMs for Scalable and Cost Effective Side-Channel Patching
arxiv_fulltext·2023-08-24
ZeroLeak: Using LLMs for Scalable and Cost Effective Side-Channel Patching
ZeroLeak: Using LLMs for Scalable and Cost Effective Side-Channel Patching
M. Caner Tol
Worcester Polytechnic Institute
[email protected]
Berk Sunar
Worcester Polytechnic Institute
[email protected]
plain
plain
### Abstract
Security critical software, e.g., OpenSSL, comes with numerous side-channel leakages left unpatched due to a lack of resources or experts. The situation will only worsen as the pace of code development accelerates, with developers relying on Large Language Models (LLMs) to automatically generate code. In this work, we explore the use of LLMs in generating patches for vulnerable code with microarchitectural side-channel leakages. For this, we investigate the generative abilities of powerful LLMs by carefully crafting prompts following a zero-shot learning approach. All g
arXiv
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
arxiv_fulltext·2023-08-23
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
M. Mehdi Kholoosi12,
M. Ali Babar12,
Cemal Yilmaz3
1 School of Computer Science, CREST, The University of Adelaide, Adelaide, Australia
2 Cyber Security Cooperative Research Centre, Australia
3 Faculty of Engineering and Natural Sciences, Sabanci University, Istanbul, 34956, Turkey
Emails: [email protected], [email protected], [email protected]
## Abstract
Timing attacks are considered one of the most damaging side-channel attacks. These attacks exploit timing fluctuations caused by certain operations to disclose confidential information to an attacker. For instance, in asymmetric encryption, operations such as multiplication and division can cause time-varying execution times th
arXiv
SafeBet: Secure, Simple, and Fast Speculative Execution
arxiv_fulltext·2023-06-13
SafeBet: Secure, Simple, and Fast Speculative Execution
empty
plain
## Abstract
Spectre attacks exploit microprocessor speculative execution to read and transmit forbidden data outside the attacker's trust domain and sandbox.
Recent hardware schemes allow potentially-unsafe speculative accesses but prevent the secret's transmission by delaying all or many of the access-dependent instructions even in the predominantly-common, no-attack case, which incurs performance loss and hardware complexity.
Instead, we propose which allows only, and in the common case does not delay most, safe accesses. We first consider the simple case
without (i) code control flow transfer across trust domains or (ii) data memory sandbox boundary changes (i.e., some locations dynamically move across sandboxes);
and then extend to the complex cases with these behaviors.
arXiv
Speculative Buffer Overflows: Attacks and Defenses
arxiv_fulltext·2018-07-10
Speculative Buffer Overflows: Attacks and Defenses
[Spectre1.1]Speculative Buffer Overflows: Attacks and Defenses
Vladimir Kiriansky
[email protected]
Carl Waldspurger
[email protected]
[1]
red
changebar
#1
changebar
Bear
SLoth
\"ive
[1] #1
[1] #1
[1] #1
#1
[1]Spectre#1
linenumcolorrgb0.5,0,0.5
myschedulergb0.858, 0.188, 0.478
[c]xleftmargin=16pt
[asm]xleftmargin=16pt
linenumcolor
FancyVerbLine
## Abstract
Practical attacks that exploit speculative execution can leak
confidential information via microarchitectural side channels. The
recently-demonstrated Spectre attacks leverage
speculative loads which circumvent access checks to read
memory-resident secrets, transmitting them to an attacker using
cache timing or other covert communication channels.
We introduce 1.1, a new Spectre-v1 variant that
leverages speculative st
Bugzilla
kernel: NetSpectre - observing speculative execution gadgets across network via statistical analysis.
bugzilla·2018-07-04·CVSS 5.6
[MEDIUM] kernel: NetSpectre - observing speculative execution gadgets across network via statistical analysis.
kernel: NetSpectre - observing speculative execution gadgets across network via statistical analysis.
“NetSpectre: Read Arbitrary Memory over Network” is the first concept of the spectre variant 1 abusing speculative execution across a network. It allows a remote attacker to abuse spectre “gadgets” available in the code path accessible in the operating systems network stack. The attacker sends a series of crafted requests to the target system and measures the response time to leak a secret value from the victim’s memory. The response time of these attacks allow an attacker to deduce a secret value from the victims memory.
This attack requires two gadgets to be available to the attacker, either in user space or kernel space.
These gadgets are:
Leak gadget - accesses a stream at an attac
Bugzilla
firefox: mitigations against spectre via javascript
bugzilla·2018-01-08·CVSS 5.6
CVE-2017-5754 [MEDIUM] firefox: mitigations against spectre via javascript
firefox: mitigations against spectre via javascript
Mozilla has issued an advisory (mfsa2018-01) for Firefox 57.0.4 that implements a short term mitigation for spectre based javascript attacks.
CVE-2017-5754 CVE-2017-5753
References:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-01/
Discussion:
(In reply to Sam Fowler from comment #3)
> "The precision of performance.now() has been reduced from 5μs to 20μs"
According to the following Mozilla blog post:
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
this mitigation is going to be include in 52 ESR in version 52.6 ESR.
---
Statement:
Mozilla has confirmed that similar to "Meltdown" and "Spectre" which are a new class of timing attacks which affect modern CPUs, it is possible t
Bugzilla
CVE-2017-5753 kernel: hw: cpu: speculative execution bounds-check bypass [fedora-all]
bugzilla·2018-01-03·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753 kernel: hw: cpu: speculative execution bounds-check bypass [fedora-all]
CVE-2017-5753 kernel: hw: cpu: speculative execution bounds-check bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-5753 hw: cpu: speculative execution bounds-check bypass
bugzilla·2017-12-01·CVSS 5.6
CVE-2017-5753 [MEDIUM] CVE-2017-5753 hw: cpu: speculative execution bounds-check bypass
CVE-2017-5753 hw: cpu: speculative execution bounds-check bypass
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited.
Variant CVE-2017-5753 triggers the speculative execution by performing a bounds-check bypass. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the sy
CWE
Processor Optimization Removal or Modification of Security-critical Code
mitre_cwe·CVSS 5.6
[MEDIUM] CWE-1037 Processor Optimization Removal or Modification of Security-critical Code
CWE-1037: Processor Optimization Removal or Modification of Security-critical Code
The developer builds a security-critical protection mechanism into the software, but the processor optimizes the execution of the program such that the mechanism is removed or modified.
Modes of Introduction:
Phase: Architecture and Design
Note: Optimizations built into the design of the processor can have unintended consequences during the execution of an application.
Common Consequences:
Scope: Integrity. Impact: Bypass Protection Mechanism. A successful exploitation of this weakness will change the order of an application's execution and will likely be used to bypass specific protection mechanisms. This bypass can be exploited further to potentially read data that should otherwise be unaccessible.
Det
CWE
Exposure of Sensitive Information during Transient Execution
mitre_cwe
CWE-1420 Exposure of Sensitive Information during Transient Execution
CWE-1420: Exposure of Sensitive Information during Transient Execution
A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.
When operations execute but do not commit to the processor's
architectural state, this is commonly referred to as transient
execution. This behavior can occur when the processor mis-predicts an
outcome (such as a branch target), or when a processor event (such as
an exception or microcode assist, etc.) is handled after younger
operations have already executed. Operations that execute transiently
may exhibit observable discrepancies (CWE-203) in covert channels
[REF-1400] such as data caches. Observable discrepancies of this kind
can be detec
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4609http://nvidia.custhelp.com/app/answers/detail/a_id/4611http://nvidia.custhelp.com/app/answers/detail/a_id/4613http://nvidia.custhelp.com/app/answers/detail/a_id/4614http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txthttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txthttp://www.kb.cert.org/vuls/id/584653http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/102371http://www.securitytracker.com/id/1040071http://xenbits.xen.org/xsa/advisory-254.htmlhttps://access.redhat.com/errata/RHSA-2018:0292https://access.redhat.com/security/vulnerabilities/speculativeexecutionhttps://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/https://cdrdv2.intel.com/v1/dl/getContent/685359https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://cert.vde.com/en-us/advisories/vde-2018-002https://cert.vde.com/en-us/advisories/vde-2018-003https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityhttps://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.htmlhttps://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixeshttps://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002https://seclists.org/bugtraq/2019/Jun/36https://security.gentoo.org/glsa/201810-06https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.htmlhttps://security.netapp.com/advisory/ntap-20180104-0001/https://spectreattack.com/https://support.citrix.com/article/CTX231399https://support.f5.com/csp/article/K91229003https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_ushttps://support.lenovo.com/us/en/solutions/LEN-18282https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannelhttps://usn.ubuntu.com/3540-1/https://usn.ubuntu.com/3540-2/https://usn.ubuntu.com/3541-1/https://usn.ubuntu.com/3541-2/https://usn.ubuntu.com/3542-1/https://usn.ubuntu.com/3542-2/https://usn.ubuntu.com/3549-1/https://usn.ubuntu.com/3580-1/https://usn.ubuntu.com/3597-1/https://usn.ubuntu.com/3597-2/https://usn.ubuntu.com/usn/usn-3516-1/https://www.debian.org/security/2018/dsa-4187https://www.debian.org/security/2018/dsa-4188https://www.exploit-db.com/exploits/43427/https://www.kb.cert.org/vuls/id/180049https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/https://www.synology.com/support/security/Synology_SA_18_01https://www.vmware.com/us/security/advisories/VMSA-2018-0002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/4609http://nvidia.custhelp.com/app/answers/detail/a_id/4611http://nvidia.custhelp.com/app/answers/detail/a_id/4613http://nvidia.custhelp.com/app/answers/detail/a_id/4614http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txthttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txthttp://www.kb.cert.org/vuls/id/584653http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/102371http://www.securitytracker.com/id/1040071http://xenbits.xen.org/xsa/advisory-254.htmlhttps://access.redhat.com/errata/RHSA-2018:0292https://access.redhat.com/security/vulnerabilities/speculativeexecutionhttps://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/https://cdrdv2.intel.com/v1/dl/getContent/685359https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfhttps://cert.vde.com/en-us/advisories/vde-2018-002https://cert.vde.com/en-us/advisories/vde-2018-003https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityhttps://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.htmlhttps://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixeshttps://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2018/07/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.html
+ 32 more references
2018-01-04
Published