CVE-2024-28956 — Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution in Intel-microcode
Severity
5.7MEDIUMNVD
EPSS
0.2%
top 54.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 13
Latest updateMay 27
Description
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVSS vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Packages6 packages
🔴Vulnerability Details
3OSV▶
CVE-2024-28956: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authent↗2025-05-13
GHSA▶
GHSA-hwrg-xmjh-93xc: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authent↗2025-05-13