cbcvebase.
CVE-2018-12126
published 2019-05-30

CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to…

PriorityP425medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
1.51%
71.8th percentile
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

Affected

24 ranges
VendorProductVersion rangeFixed in
applemacos_mojave_10.14.5_security_update_2019-003_high_sierra_security_update_2019-0
debianintel-microcode< intel-microcode 3.20190514.1 (bookworm)intel-microcode 3.20190514.1 (bookworm)
debianlinux< intel-microcode 3.20190514.1 (bookworm)intel-microcode 3.20190514.1 (bookworm)
debianxen< intel-microcode 3.20190514.1 (bookworm)intel-microcode 3.20190514.1 (bookworm)
fedoraprojectfedora
intel_corporationcentral_proccve-2018-12126essing_units
linuxlinux_kernel>= 0 < 4.19.37-24.19.37-2
linuxlinux_kernel>= 0 < 4.19.37-24.19.37-2
linuxlinux_kernel>= 0 < 4.19.37-24.19.37-2
linuxlinux_kernel>= 0 < 4.19.37-24.19.37-2
linuxlinux_kernel>= 0 < 3.13.0-170.2203.13.0-170.220
linuxlinux_kernel>= 0 < 4.4.0-148.1744.4.0-148.174
linuxlinux_kernel>= 0 < 4.15.0-50.544.15.0-50.54
paloaltopan-os
paloaltopanorama
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.462.0.0+dfsg-2ubuntu1.46
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.381:2.5+dfsg-5ubuntu10.38
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.131:2.11+dfsg-1ubuntu7.13
redhatlibvirt>= 0 < 1.3.1-1ubuntu10.261.3.1-1ubuntu10.26
redhatlibvirt>= 0 < 4.0.0-1ubuntu8.104.0.0-1ubuntu8.10
xenxen>= 0 < 4.11.1+92-g6c33308a8d-14.11.1+92-g6c33308a8d-1
xenxen>= 0 < 4.11.1+92-g6c33308a8d-14.11.1+92-g6c33308a8d-1
xenxen>= 0 < 4.11.1+92-g6c33308a8d-14.11.1+92-g6c33308a8d-1
xenxen>= 0 < 4.11.1+92-g6c33308a8d-14.11.1+92-g6c33308a8d-1

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.