CVE-2017-5925

EUVD-2017-15000
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
allwinnera64
-
amdathlon_ii_640_x4
-
amde-350
-
amdfx-8120_8-core
-
amdfx-8320_8-core
-
amdfx-8350_8-core
-
amdphenom_9550_4-core
-
intelatom_c2750
-
intelceleron_n2840
-
intelcore_i5_m480
-
intelcore_i7-2620qm
-
intelcore_i7-3632qm
-
intelcore_i7-4500u
-
intelcore_i7-6700k
-
intelcore_i7_920
-
intelxeon_e3-1240_v5
-
intelxeon_e5-2658_v2
-
nvidiategra_k1_cd570m-a1
-
nvidiategra_k1_cd580m-a1
-
samsungexynos_5800
-
𝑥
= Vulnerable software versions