Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-5753

Severity
5.6MEDIUM
EPSS
94.3%
top 0.05%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 4
Latest updateMar 15

Description

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:NExploitability: 1.1 | Impact: 4.0

Affected Packages52 packages

NVDvmware/fusion8.0.08.5.9
NVDvmware/workstation12.0.012.5.8
NVDsynology/router_manager1.11.1.7-6941-1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.04, 17.10

Patches

🔴Vulnerability Details

15
OSV
linux-hwe vulnerabilities2018-03-15
OSV
linux-kvm vulnerabilities2018-01-29
OSV
linux, linux-aws, linux-euclid vulnerabilities2018-01-23
OSV
linux vulnerabilities2018-01-23
Kernel
Merge branch 'kvm-insert-lfence'2018-01-16

💥Exploits & PoCs

1
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure2018-01-03

🔍Detection Rules

2
Suricata
ET EXPLOIT Possible Spectre PoC Download In Progress2018-01-10
Suricata
ET WEB_CLIENT Spectre Exploit Javascript2018-01-09

📋Vendor Advisories

19
Ubuntu
Linux kernel vulnerabilities2018-03-15
Ubuntu
Linux kernel (HWE) vulnerabilities2018-03-15
Ubuntu
Linux kernel vulnerabilities2018-02-22
Ubuntu
Linux kernel (KVM) vulnerabilities2018-01-29
Ubuntu
Linux kernel vulnerabilities2018-01-23

🕵️Threat Intelligence

5
Fortinet
Meltdown/Spectre Update2018-01-30
Qualys
Processor Vulnerabilities – Meltdown and Spectre2018-01-04
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes2018-01-04
Sentinelone
SentinelOne is Compatible with “Meltdown” and “Spectre” Fixes2018-01-04
Qualys
Processor Vulnerabilities - Meltdown and Spectre | Qualys2018-01-04

💬Community

3
Bugzilla
firefox: mitigations against spectre via javascript2018-01-08
Bugzilla
CVE-2017-5753 kernel: hw: cpu: speculative execution bounds-check bypass [fedora-all]2018-01-03
Bugzilla
CVE-2017-5753 hw: cpu: speculative execution bounds-check bypass2017-12-01