PT-2019-4073 · Intel+9 · Intel Cpus+9

Publicado

2019-07-09

·

Atualizado

2024-05-29

·

CVE-2019-1125

CVSS v3.1

5.6

Média

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified) Intel CPUs (affected versions not specified) AMD CPUs (affected versions not specified) ARM CPUs (affected versions not specified) Linux (affected versions not specified)
Description An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. This vulnerability is a variant of the Spectre Variant 1 speculative execution side channel vulnerability.
Recommendations Apply the security update released by Microsoft on July 9, 2019, which addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. For Linux, ChromeOS, and Windows, apply the proposed method of protection that is effective against this vulnerability. As a temporary workaround, consider restricting access to sensitive information and limiting the use of affected systems until a patch is applied.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04636
CESA-2019_2405
CESA-2019_2411
CESA-2019_2473
CESA-2019_2600
CVE-2019-1125
DLA-1884-1
DLA-1885-1
DSA-4495-1
DSA-4497-1
MGASA-2019-0220
MGASA-2019-0221
MGASA-2019-0333
OPENSUSE-SU-2019:1923-1
OPENSUSE-SU-2019:1924-1
OPENSUSE-SU-2019_1923-1
OPENSUSE-SU-2019_1924-1
RHSA-2019:2405
RHSA-2019:2411
RHSA-2019:2473
RHSA-2019:2476
RHSA-2019:2600
RHSA-2019:2609
RHSA-2019:2695
RHSA-2019:2696
RHSA-2019:2730
RHSA-2019:2899
RHSA-2019:2900
RHSA-2019:2975
RHSA-2019:3011
RHSA-2019:3220
RHSA-2019_2405
RHSA-2019_2411
RHSA-2019_2473
RHSA-2019_2600
RHSA-2019_2609
SUSE-SU-2019:14157-1
SUSE-SU-2019:2068-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2070-1
SUSE-SU-2019:2071-1
SUSE-SU-2019:2072-1
SUSE-SU-2019:2073-1
SUSE-SU-2019:2262-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
SUSE-SU-2019_14157-1
USN-4093-1
USN-4094-1
USN-4095-1
USN-4095-2
USN-4096-1

Produtos afetados

Amd Cpus
Arm Cpu
Centos
Huawei Vrp
Intel Cpus
Linux
Red Hat
Suse
Ubuntu
Windows