PT-2018-1001 · Microsoft+7 · Windows+11

Jann Horn

·

Published

2018-01-03

·

Updated

2025-12-10

·

CVE-2017-5753

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Systems with microprocessors utilizing speculative execution and branch prediction (affected versions not specified)
Description The issue is related to microprocessors utilizing speculative execution and branch prediction, which may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. This can be used to read the content of memory across a trusted boundary, leading to information disclosure. Microsoft released several updates to help mitigate the vulnerability, preventing attackers from triggering a weakness in the CPU that could allow the contents of memory to be disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_2394
ALSA-2025_10379
ALSA-2025_10669
ALSA-2025_10670
ALSA-2025_11298
ALSA-2025_11299
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_13589
ALSA-2025_13590
ALSA-2025_16880
ALSA-2025_18281
ALSA-2025_19102
ALSA-2025_19103
ALSA-2025_19409
ALSA-2025_20518
ALSA-2025_2473
ALSA-2025_2474
ALSA-2025_3260
ALSA-2025_3264
ALSA-2025_7423
ALSA-2025_8743
ALSA-2025_8744
ALSA-2025_9080
ALT-PU-2018-1025
ALT-PU-2018-1046
ALT-PU-2018-1047
ALT-PU-2018-1048
ALT-PU-2018-2253
BDU:2018-00002
CESA-2018_0151
CESA-2018_0512
CVE-2017-5753
DLA-1422-1
DLA-1422-2
DLA-1423-1
DLA-1731-1
DLA-1731-2
DSA-4120-1
DSA-4120-2
DSA-4187-1
DSA-4188-1
DSA-4469-1
ELSA-2018-0007
ELSA-2018-0008
ELSA-2018-4004
ELSA-2018-4020
ELSA-2018-4022
ELSA-2018-4285
ELSA-2018-4289
ELSA-2019-4785
MGASA-2018-0071
MGASA-2018-0073
MGASA-2018-0074
MGASA-2018-0076
MGASA-2018-0077
MGASA-2018-0080
MGASA-2018-0082
MGASA-2018-0106
MGASA-2018-0107
MGASA-2018-0125
MGASA-2018-0126
MGASA-2018-0127
OPENSUSE-SU-2018_0022-1
OPENSUSE-SU-2018_0023-1
OPENSUSE-SU-2018_0326-1
OPENSUSE-SU-2018_0459-1
OPENSUSE-SU-2018_1623-1
OPENSUSE-SU-2018_2119-1
OPENSUSE-SU-2021:1212-1
OPENSUSE-SU-2021:2861-1
OPENSUSE-SU-2021_1212-1
OPENSUSE-SU-2021_2861-1
OPENSUSE-SU-2024:10728-1
OPENSUSE-SU-2024:11506-1
OPENSUSE-SU-2024:11513-1
OPENSUSE-SU-2024:11520-1
OPENSUSE-SU-2024:13704-1
OPENSUSE-SU-2025_1195-1
OPENSUSE-SU-2025_1263-1
RHSA-2018:0010
RHSA-2018:0016
RHSA-2018:0017
RHSA-2018:0018
RHSA-2018:0020
RHSA-2018:0021
RHSA-2018:0022
RHSA-2018:0151
RHSA-2018:0182
RHSA-2018:0292
RHSA-2018:0464
RHSA-2018:0496
RHSA-2018:0512
RHSA-2018:0654
RHSA-2018_0016
RHSA-2018_0151
RHSA-2018_0292
RHSA-2018_0512
SUSE-SU-2018:0010-1
SUSE-SU-2018:0011-1
SUSE-SU-2018:0012-1
SUSE-SU-2018:0031-1
SUSE-SU-2018:0040-1
SUSE-SU-2018:0069-1
SUSE-SU-2018:0113-1
SUSE-SU-2018:0114-1
SUSE-SU-2018:0115-1
SUSE-SU-2018:0131-1
SUSE-SU-2018:0171-1
SUSE-SU-2018:0180-1
SUSE-SU-2018:0213-1
SUSE-SU-2018:0219-1
SUSE-SU-2018:0285-1
SUSE-SU-2018:0438-1
SUSE-SU-2018:0472-1
SUSE-SU-2018:0552-1
SUSE-SU-2018:0552-2
SUSE-SU-2018:0601-1
SUSE-SU-2018:0609-1
SUSE-SU-2018:0638-1
SUSE-SU-2018:0678-1
SUSE-SU-2018:0909-1
SUSE-SU-2018:1368-1
SUSE-SU-2018:1376-1
SUSE-SU-2018:1603-1
SUSE-SU-2018:1658-1
SUSE-SU-2018:1699-1
SUSE-SU-2018:1699-2
SUSE-SU-2018:2092-1
SUSE-SU-2018:2150-1
SUSE-SU-2018:2222-1
SUSE-SU-2018:2528-1
SUSE-SU-2018_0179-1
SUSE-SU-2018_0191-1
SUSE-SU-2019:0222-1
SUSE-SU-2019:0765-1
SUSE-SU-2019:1550-1
SUSE-SU-2019:2430-1
SUSE-SU-2019_0222-1
SUSE-SU-2019_0765-1
SUSE-SU-2021:2861-1
SUSE-SU-2021:2862-1
SUSE-SU-2021:3929-1
SUSE-SU-2021_2861-1
SUSE-SU-2021_2862-1
SUSE-SU-2023:1800-1
SUSE-SU-2023:1801-1
SUSE-SU-2023:1802-1
SUSE-SU-2023:1803-1
SUSE-SU-2023:1811-1
SUSE-SU-2023:1848-1
SUSE-SU-2023:1892-1
SUSE-SU-2023:1894-1
SUSE-SU-2023:1897-1
SUSE-SU-2023:1992-1
SUSE-SU-2023:2232-1
SUSE-SU-2023:2506-1
SUSE-SU-2023:2805-1
SUSE-SU-2023_1800-1
SUSE-SU-2023_1801-1
SUSE-SU-2023_1802-1
SUSE-SU-2023_1803-1
SUSE-SU-2023_1811-1
SUSE-SU-2023_1848-1
SUSE-SU-2023_1892-1
SUSE-SU-2023_1894-1
SUSE-SU-2023_1897-1
SUSE-SU-2023_1992-1
SUSE-SU-2023_2232-1
SUSE-SU-2023_2506-1
SUSE-SU-2023_2805-1
SUSE-SU-2025:02099-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_02099-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1
USN-3516-1
USN-3521-1
USN-3530-1
USN-3540-1
USN-3540-2
USN-3541-1
USN-3541-2
USN-3542-1
USN-3542-2
USN-3549-1
USN-3580-1
USN-3597-1
USN-3597-2

Affected Products

Alt Linux
Centos
Edge
Ibm Aix
Internet Explorer
Sql Server
Windows
Red Hat
Suse
Ubuntu
Vmware Vcenter
Vmware Workstation