CVE-2024-45332
published 2025-05-13CVE-2024-45332: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for…
PriorityP422medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.25%
16.8th percentile
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250512.1~deb12u1 (bookworm) | intel-microcode 3.20250512.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv4.05.7MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-05-27·CVSS 5.7
CVE-2024-28956 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2025-20012,
CVE-2025-24495)
Michal Raviv
OSV
CVE-2024-45332: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predi
osv·2025-05-13·CVSS 5.7
CVE-2024-45332 [MEDIUM] CVE-2024-45332: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predi
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
GHSA
GHSA-m3hm-6gqp-pf9f: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predi
ghsa_unreviewed·2025-05-13
CVE-2024-45332 [MEDIUM] GHSA-m3hm-6gqp-pf9f: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predi
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-05-27·CVSS 5.6
CVE-2024-45332 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtai
Red Hat
microcode_ctl: Exposure of sensitive information
vendor_redhat·2025-05-13·CVSS 5.7
CVE-2024-45332 [MEDIUM] CWE-1423 microcode_ctl: Exposure of sensitive information
microcode_ctl: Exposure of sensitive information
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Statement: Intel has recommended through its official advisory that users of the affected processors search their hardware vendor for firmware updates.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Fix deferred
Debian
CVE-2024-45332: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
vendor_debian·2024·CVSS 5.7
CVE-2024-45332 [MEDIUM] CVE-2024-45332: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
trixie: resolved (fixed in 3.20250512.1)
No detection rules found.
No public exploits indexed.
2025-05-13
Published