CVE-2023-23583
published 2023-11-14CVE-2023-23583: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.73%
75.2th percentile
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20231114.1~deb12u1 (bookworm) | intel-microcode 3.20231114.1~deb12u1 (bookworm) |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerability
vendor_ubuntu·2023-11-17
CVE-2023-23583 Intel Microcode vulnerability
Title: Intel Microcode vulnerability
Summary: The system could be made to crash or expose sensitive information under certain
conditions.
Benoit Morgan, Paul Grosen, Thais Moreira Hamasaki, Ke Sun, Alyssa Milburn,
Hisham Shafi, Nir Shlomovich, Tavis Ormandy, Daniel Moghimi, Josh Eads, Salman
Qazi, Alexandra Sandulescu, Andy Nguyen, Eduardo Vela, Doug Kwan, and Kostik
Shtoyk discovered that some Intel(R) Processors did not properly handle certain
sequences of processor instructions. A local attacker could possibly use this to
cause a core hang (resulting in a denial of service), gain access to sensitive
information or possibly escalate their privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
hw: Intel: execution of MOVSB instructions with redundant REX prefix leads to unintended system behavior
vendor_redhat·2023-11-14·CVSS 8.8
CVE-2023-23583 [HIGH] CWE-1281 hw: Intel: execution of MOVSB instructions with redundant REX prefix leads to unintended system behavior
hw: Intel: execution of MOVSB instructions with redundant REX prefix leads to unintended system behavior
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
A security vulnerability was found in some Intel processors. Execution of REP MOVSB instructions with a redundant REX prefix may result in execution continuing at an incorrect EIP address after a micro-architectural event occurs, potentially allowing privilege escalation, information disclosure and/or a denial of service via local access.
Statement: This is a hardware flaw that affects select Intel processors and is not a Red Hat Enterprise Lin
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-23583
vendor_chrome·2023-10-24·CVSS 8.8
CVE-2023-23583 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2023-23583
Long Term Support Channel Update for ChromeOS
CVE-2023-23583
Debian
CVE-2023-23583: intel-microcode - Sequence of processor instructions leads to unexpected behavior for some Intel(R...
vendor_debian·2023·CVSS 8.8
CVE-2023-23583 [HIGH] CVE-2023-23583: intel-microcode - Sequence of processor instructions leads to unexpected behavior for some Intel(R...
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20231114.1~deb12u1)
bullseye: resolved (fixed in 3.20231114.1~deb11u1)
forky: resolved (fixed in 3.20231114.1)
sid: resolved (fixed in 3.20231114.1)
trixie: resolved (fixed in 3.20231114.1)
GHSA
GHSA-9cgg-v86h-hw54: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable esc
ghsa_unreviewed·2023-11-14
CVE-2023-23583 [HIGH] CWE-1281 GHSA-9cgg-v86h-hw54: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable esc
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
OSV
CVE-2023-23583: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable esc
osv·2023-11-14·CVSS 7.8
CVE-2023-23583 [HIGH] CVE-2023-23583: Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable esc
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
No detection rules found.
No public exploits indexed.
Talos
We all just need to agree that ad blockers are good
blogs_talos·2023-11-16
We all just need to agree that ad blockers are good
## We all just need to agree that ad blockers are good
I don’t think this is a particularly bold take — but I’m not afraid to say that ad blockers are good!
Ever since I started using one sometime in 2016, my experience of using the internet has improved exponentially. I can finally easily find a recipe for dinner on a random influencer’s blog, get a faster answer to “how to replace my car’s headlights” and likely avoid hundreds of pieces of malvertising .
But their use has increasingly come into question with YouTube’s new policies on preventing users from using ad blockers on its site, with new warnings saying the user has a certain number of videos they can watch before they must allowlist youtube.com in their ad blocker, thus allowing the site to display ads before YouTube videos.
Talos
We all just need to agree that ad blockers are good
blogs_talos·2023-11-16
We all just need to agree that ad blockers are good
I don’t think this is a particularly bold take — but I’m not afraid to say that ad blockers are good!
Ever since I started using one sometime in 2016, my experience of using the internet has improved exponentially. I can finally easily find a recipe for dinner on a random influencer’s blog, get a faster answer to “how to replace my car’s headlights” and likely avoid hundreds of pieces of malvertising.
But their use has increasingly come into question with YouTube’s new policies on preventing users from using ad blockers on its site, with new warnings saying the user has a certain number of videos they can watch before they must allowlist youtube.com in their ad blocker, thus allowing the site to display ads before YouTube videos.
The second this popped up for me two weeks ago, I immedia
Bleepingcomputer
Citrix Hypervisor gets hotfix for new Reptar Intel CPU flaw
blogs_bleepingcomputer·2023-11-15·CVSS 8.8
CVE-2023-23583 [HIGH] Citrix Hypervisor gets hotfix for new Reptar Intel CPU flaw
## Citrix Hypervisor gets hotfix for new Reptar Intel CPU flaw
## Bill Toulas
Citrix has released hotfixes for two vulnerabilities impacting Citrix Hypervisor, one of them being the "Reptar" high-severity flaw that affects Intel CPUs for desktop and server systems.
The Citrix Hypervisor (formerly XenServer) is an enterprise-level virtualization platform for deploying and managing virtualized environments.
The hotfixes address vulnerabilities tracked as CVE-2023-23583 and CVE-2023-46835. The former is a security issue that Intel disclosed yesterday and impacts the 'Ice Lake' (2019) and later processor generations.
Known as a 'Redundant Prefix Issue', the vulnerability involves the execution of a specific instruction (REP MOVSB) with a redundant REX prefix, potentially leading to system
Bleepingcomputer
New Reptar CPU flaw impacts Intel desktop and server systems
blogs_bleepingcomputer·2023-11-14·CVSS 8.8
CVE-2023-23583 [HIGH] New Reptar CPU flaw impacts Intel desktop and server systems
## New Reptar CPU flaw impacts Intel desktop and server systems
## Sergiu Gatlan
Intel has fixed a high-severity CPU vulnerability in its modern desktop, server, mobile, and embedded CPUs, including the latest Alder Lake, Raptor Lake, and Sapphire Rapids microarchitectures.
Attackers can exploit the flaw—tracked as CVE-2023-23583 and described as a 'Redundant Prefix Issue'—to escalate privileges, gain access to sensitive information, or trigger a denial of service state (something that could prove very costly for cloud providers).
"Under certain microarchitectural conditions, Intel has identified cases where execution of an instruction (REP MOVSB) encoded with a redundant REX prefix may result in unpredictable system behavior resulting in a system crash/hang, or, in some limited scenar
http://www.openwall.com/lists/oss-security/2023/11/14/4http://www.openwall.com/lists/oss-security/2023/11/14/5http://www.openwall.com/lists/oss-security/2023/11/14/6http://www.openwall.com/lists/oss-security/2023/11/14/7http://www.openwall.com/lists/oss-security/2023/11/14/8http://www.openwall.com/lists/oss-security/2023/11/14/9https://lists.debian.org/debian-lts-announce/2023/12/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20231116-0015/https://www.debian.org/security/2023/dsa-5563https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.htmlhttp://www.openwall.com/lists/oss-security/2023/11/14/4http://www.openwall.com/lists/oss-security/2023/11/14/5http://www.openwall.com/lists/oss-security/2023/11/14/6http://www.openwall.com/lists/oss-security/2023/11/14/7http://www.openwall.com/lists/oss-security/2023/11/14/8http://www.openwall.com/lists/oss-security/2023/11/14/9https://lists.debian.org/debian-lts-announce/2023/12/msg00012.htmlhttps://security.netapp.com/advisory/ntap-20231116-0015/https://www.debian.org/security/2023/dsa-5563https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html
2023-11-14
Published