CVE-2023-28746
published 2024-03-14CVE-2023-28746: Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an…
PriorityP426medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.55%
42.1th percentile
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240312.1~deb12u1 (bookworm) | intel-microcode 3.20240312.1~deb12u1 (bookworm) |
| debian | linux | < intel-microcode 3.20240312.1~deb12u1 (bookworm) | intel-microcode 3.20240312.1~deb12u1 (bookworm) |
| debian | xen | < intel-microcode 3.20240312.1~deb12u1 (bookworm) | intel-microcode 3.20240312.1~deb12u1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.216-1 | 5.10.216-1 |
| linux | linux_kernel | >= 0 < 6.1.82-1 | 6.1.82-1 |
| linux | linux_kernel | >= 0 < 6.7.9-2 | 6.7.9-2 |
| linux | linux_kernel | >= 0 < 6.7.9-2 | 6.7.9-2 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| xen | xen | >= 0 < 4.17.5+23-ga4e5191dc0-1 | 4.17.5+23-ga4e5191dc0-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-05-29·CVSS 6.1
CVE-2023-46103 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubunt
Microsoft
Intel: CVE-2023-28746 Register File Data Sampling (RFDS)
vendor_msrc·2024-03-12·CVSS 6.5
CVE-2023-28746 [MEDIUM] CWE-1037 Intel: CVE-2023-28746 Register File Data Sampling (RFDS)
Intel: CVE-2023-28746 Register File Data Sampling (RFDS)
Description: This CVE was assigned by Intel. Please see CVE-2023-28746 on CVE.org for more information.
FAQ: Why is this Intel CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in certain processor models offered by Intel. The mitigation for this vulnerability requires a firmware update, and a corresponding Windows updates enables the mitigation. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and are not vulnerable to the issue when paired with the firmware update. Please see the following for more information: https://www.intel.com/content/www/us/en/developer/articles/technical/softwaresecurity-guidance/advisory-guidan
Red Hat
kernel: Local information disclosure on Intel(R) Atom(R) processors
vendor_redhat·2024-02-14·CVSS 6.5
CVE-2023-28746 [MEDIUM] CWE-1342 kernel: Local information disclosure on Intel(R) Atom(R) processors
kernel: Local information disclosure on Intel(R) Atom(R) processors
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A vulnerability was found in some Intel Atom Processor's microcode. This issue may allow a malicious actor to achieve a local information disclosure, impacting the data confidentiality of the targeted system.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 6) - Out of support scope
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Packa
Debian
CVE-2023-28746: intel-microcode - Information exposure through microarchitectural state after transient execution ...
vendor_debian·2023·CVSS 6.5
CVE-2023-28746 [MEDIUM] CVE-2023-28746: intel-microcode - Information exposure through microarchitectural state after transient execution ...
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid: resolved (fixed in 3.20240312.1)
trixie: resolved (fixed in 3.20240312.1)
OSV
intel-microcode vulnerabilities
osv·2024-05-29·CVSS 6.1
CVE-2023-22655 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. (CVE-2023-28746)
It
OSV
CVE-2023-28746: Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allo
osv·2024-03-14·CVSS 6.5
CVE-2023-28746 [MEDIUM] CVE-2023-28746: Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allo
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
GHSA
GHSA-36c8-x5g7-w9x4: Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allo
ghsa_unreviewed·2024-03-14
CVE-2023-28746 [MEDIUM] CWE-1342 GHSA-36c8-x5g7-w9x4: Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allo
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
bugzilla·2024-03-21·CVSS 6.5
CVE-2023-28746 [MEDIUM] CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
CVE-2023-28746 kernel: Local information disclosure on Intel(R) Atom(R) processors
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00898.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270731]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:5101 https://access.redhat.com/errata/RHSA-2024:5101
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:8158 htt
Bleepingcomputer
Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
blogs_bleepingcomputer·2024-03-12·CVSS 5.5
[MEDIUM] Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
## Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
## Lawrence Abrams
24 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
18 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
The total count of 60 flaws does not include 4 Microsoft Edge flaws fixed on March 7th.
Furthermore, Microsoft did not disclose any zero-days as part of today's Patch Tuesday updates.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5035853 update and the Windows 10 KB5035845 update .
## Flaws of interest
This month's Patch Tuesday does not fix any zero-day vulnerabilities but does include some in
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
# The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs
2024/03/12
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager, which addresses 44 CVEs.
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs 2024/03/12 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager , which addresses 44 CVEs.
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs Mar 12, 2024 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager , which addresses 44 CVE
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs Mar 12, 2024 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Programme. The largest is the update for Experience Manager , which addresses 44 C
http://www.openwall.com/lists/oss-security/2024/03/12/13https://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/https://lists.fedoraproject.org/archives/list/[email protected]/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00898.htmlhttp://www.openwall.com/lists/oss-security/2024/03/12/13http://xenbits.xen.org/xsa/advisory-452.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/EIUICU6CVJUIB6BPJ7P5QTPQR5VOBHFK/https://lists.fedoraproject.org/archives/list/[email protected]/message/H63LGAQXPEVJOES73U4XK65I6DASOAAG/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZON4TLXG7TG4A2XZG563JMVTGQW4SF3A/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00898.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.html
2024-03-14
Published