CVE-2021-0145
published 2022-02-09CVE-2021-0145: Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.33%
25.4th percentile
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20220207.1 (bookworm) | intel-microcode 3.20220207.1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Intel Microcode vulnerabilities
osv·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Intel Microcode vulnerabilities
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to ex
OSV
intel-microcode vulnerabilities
osv·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)
GHSA
GHSA-8qrx-mx6c-rjjw: Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure v
ghsa_unreviewed·2022-02-11
CVE-2021-0145 [MEDIUM] CWE-665 GHSA-8qrx-mx6c-rjjw: Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure v
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
CVE-2021-0145: Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure v
osv·2022-02-09·CVSS 5.5
CVE-2021-0145 [MEDIUM] CVE-2021-0145: Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure v
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on m
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local a
Red Hat
microcode: Fast store forward predictor - Cross Domain Training
vendor_redhat·2022-02-08·CVSS 5.5
CVE-2021-0145 [MEDIUM] CWE-665 microcode: Fast store forward predictor - Cross Domain Training
microcode: Fast store forward predictor - Cross Domain Training
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in microcode. Fast store forwarding prediction in one domain could be controlled by software previously executed in another domain. Such control helps a malicious program running in user mode (or guest VM) to trigger transient execution gadgets in supervisor mode (or VMM), potentially leading to sensitive data disclosure. Fast store forward prediction is not enabled when SSBD is set. This flaw allows an authenticated user with local access to perform information disclosure via transient execution.
Statement: Red Hat has very limited to no visi
Debian
CVE-2021-0145: intel-microcode - Improper initialization of shared resources in some Intel(R) Processors may allo...
vendor_debian·2021·CVSS 5.5
CVE-2021-0145 [MEDIUM] CVE-2021-0145: intel-microcode - Improper initialization of shared resources in some Intel(R) Processors may allo...
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolved (fixed in 3.20220207.1)
trixie: resolved (fixed in 3.20220207.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published