PT-2019-4073 · Intel+9 · Intel Cpus+9

Published

2019-07-09

·

Updated

2024-05-29

·

CVE-2019-1125

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified) Intel CPUs (affected versions not specified) AMD CPUs (affected versions not specified) ARM CPUs (affected versions not specified) Linux (affected versions not specified)
Description An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. This vulnerability is a variant of the Spectre Variant 1 speculative execution side channel vulnerability.
Recommendations Apply the security update released by Microsoft on July 9, 2019, which addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. For Linux, ChromeOS, and Windows, apply the proposed method of protection that is effective against this vulnerability. As a temporary workaround, consider restricting access to sensitive information and limiting the use of affected systems until a patch is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04636
CESA-2019_2405
CESA-2019_2411
CESA-2019_2473
CESA-2019_2600
CVE-2019-1125
DLA-1884-1
DLA-1885-1
DSA-4495-1
DSA-4497-1
MGASA-2019-0220
MGASA-2019-0221
MGASA-2019-0333
OPENSUSE-SU-2019:1923-1
OPENSUSE-SU-2019:1924-1
OPENSUSE-SU-2019_1923-1
OPENSUSE-SU-2019_1924-1
RHSA-2019:2405
RHSA-2019:2411
RHSA-2019:2473
RHSA-2019:2476
RHSA-2019:2600
RHSA-2019:2609
RHSA-2019:2695
RHSA-2019:2696
RHSA-2019:2730
RHSA-2019:2899
RHSA-2019:2900
RHSA-2019:2975
RHSA-2019:3011
RHSA-2019:3220
RHSA-2019_2405
RHSA-2019_2411
RHSA-2019_2473
RHSA-2019_2600
RHSA-2019_2609
SUSE-SU-2019:14157-1
SUSE-SU-2019:2068-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2070-1
SUSE-SU-2019:2071-1
SUSE-SU-2019:2072-1
SUSE-SU-2019:2073-1
SUSE-SU-2019:2262-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
SUSE-SU-2019_14157-1
USN-4093-1
USN-4094-1
USN-4095-1
USN-4095-2
USN-4096-1

Affected Products

Amd Cpus
Arm Cpu
Centos
Huawei Vrp
Intel Cpus
Linux
Red Hat
Suse
Ubuntu
Windows