CVE-2024-43420
published 2025-05-13CVE-2024-43420: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may…
PriorityP422medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.15%
4.4th percentile
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250512.1~deb12u1 (bookworm) | intel-microcode 3.20250512.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv4.05.7MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-05-27·CVSS 5.7
CVE-2024-28956 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2025-20012,
CVE-2025-24495)
Michal Raviv
OSV
CVE-2024-43420: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) proce
osv·2025-05-13·CVSS 5.7
CVE-2024-43420 [MEDIUM] CVE-2024-43420: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) proce
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
GHSA
GHSA-6gp3-r6r7-wq4f: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) proce
ghsa_unreviewed·2025-05-13
CVE-2024-43420 [MEDIUM] GHSA-6gp3-r6r7-wq4f: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) proce
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-05-27·CVSS 5.6
CVE-2024-45332 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtai
Red Hat
microcode_ctl: Exposure of sensitive information
vendor_redhat·2025-05-13·CVSS 5.7
CVE-2024-43420 [MEDIUM] CWE-1423 microcode_ctl: Exposure of sensitive information
microcode_ctl: Exposure of sensitive information
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Fix deferred
Debian
CVE-2024-43420: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
vendor_debian·2024·CVSS 5.7
CVE-2024-43420 [MEDIUM] CVE-2024-43420: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
trixie: resolved (fixed in 3.20250512.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-13
Published