CVE-2022-21127
published 2022-06-15CVE-2022-21127: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
5.46%
91.9th percentile
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20220510.1 (bookworm) | intel-microcode 3.20220510.1 (bookworm) |
| intel | sgx_dcap | < 1.14.100.3 | 1.14.100.3 |
| intel | sgx_psw | < 2.16.100.3 | 2.16.100.3 |
| intel | sgx_psw | < 2.17.100.3 | 2.17.100.3 |
| intel | sgx_sdk | < 2.16.100.3 | 2.16.100.3 |
| intel | sgx_sdk | < 2.17.100.3 | 2.17.100.3 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5HIGH
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Intel Microcode vulnerabilities
osv·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Intel Microcode vulnerabilities
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to ex
OSV
intel-microcode vulnerabilities
osv·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)
GHSA
GHSA-q9qj-gqmf-73c2: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable inf
ghsa_unreviewed·2022-06-16
CVE-2022-21127 [MEDIUM] CWE-459 GHSA-q9qj-gqmf-73c2: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable inf
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
CVE-2022-21127: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable inf
osv·2022-06-15·CVSS 5.5
CVE-2022-21127 [MEDIUM] CVE-2022-21127: Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable inf
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on m
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local a
Red Hat
hw: cpu: Incomplete cleanup in specific special register read operations (aka SRBDS update)
vendor_redhat·2022-06-14·CVSS 5.5
CVE-2022-21127 [MEDIUM] CWE-459 hw: cpu: Incomplete cleanup in specific special register read operations (aka SRBDS update)
hw: cpu: Incomplete cleanup in specific special register read operations (aka SRBDS update)
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in hw. Incomplete cleanup in specific special register read operations for some Intel® Processors may allow an authenticated user to enable information disclosure via local access.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party vendor a
Microsoft
Intel: CVE-2022-21127 Special Register Buffer Data Sampling Update (SRBDS Update)
vendor_msrc·2022-06-14·CVSS 5.5
CVE-2022-21127 [MEDIUM] Intel: CVE-2022-21127 Special Register Buffer Data Sampling Update (SRBDS Update)
Intel: CVE-2022-21127 Special Register Buffer Data Sampling Update (SRBDS Update)
FAQ: Why is this Intel CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in certain processor models offered by Intel. The mitigation for this vulnerability requires a firmware update, and a corresponding Windows updates enables the mitigation. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and are not vulnerable to the issue when paired with the firmware update.
Please see the following for more information:
Microsoft Advisory 220002
Intel-SA-00615
Intel: Intel
Intel Corporation: Intel Corporation
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclo
Debian
CVE-2022-21127: intel-microcode - Incomplete cleanup in specific special register read operations for some Intel(R...
vendor_debian·2022·CVSS 5.5
CVE-2022-21127 [MEDIUM] CVE-2022-21127: intel-microcode - Incomplete cleanup in specific special register read operations for some Intel(R...
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510.1)
trixie: resolved (fixed in 3.20220510.1)
No detection rules found.
No public exploits indexed.
Checkpoint
6th March – Threat Intelligence Report
blogs_checkpoint·2023-03-06
CVE-2023-0669 6th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th March, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The American fast food chain Chick-fil-A has released an announcement revealing a credential stuffing attack occurred on their website and mobile app. The attack exposed over 71K customers’ accounts data, including names, email addresses, mobile payment numbers and masked credit or debit card numbers, and threat actors may have u
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
Microsoft Critical and Important Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka flaws) in the June
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
- Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka fl
http://www.openwall.com/lists/oss-security/2022/06/16/1https://security.netapp.com/advisory/ntap-20220624-0008/https://www.debian.org/security/2022/dsa-5178https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.htmlhttp://www.openwall.com/lists/oss-security/2022/06/16/1https://security.netapp.com/advisory/ntap-20220624-0008/https://www.debian.org/security/2022/dsa-5178https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html
2022-06-15
Published