SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5925

By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

HIGH 7.5EPSS 1.58%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.58% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
allwinner/a64 · amd/athlon ii 640 x4 · amd/e-350 · amd/fx-8120 8-core · amd/fx-8320 8-core · amd/fx-8350 8-core · amd/phenom 9550 4-core · intel/atom c2750 · intel/celeron n2840 · intel/core i5 m480 · intel/core i7-2620qm · intel/core i7-3632qm · intel/core i7-4500u · intel/core i7-6700k · intel/core i7 920 · intel/xeon e3-1240 v5 · intel/xeon e5-2658 v2 · nvidia/tegra k1 cd570m-a1 · nvidia/tegra k1 cd580m-a1 · samsung/exynos 5800
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.