Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2018-3665 |
CWE-ID | CWE-200 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Intel Core M 32nm Hardware solutions / Firmware Intel Core M 45nm Hardware solutions / Firmware Intel Core i7 32nm Hardware solutions / Firmware Intel Core i7 45nm Hardware solutions / Firmware Intel Core i5 32nm Hardware solutions / Firmware Intel Core i5 45nm Hardware solutions / Firmware Intel Core i3 32nm Hardware solutions / Firmware Intel Core i3 45nm Hardware solutions / Firmware |
Vendor | Intel |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU13337
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2018-3665
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to utilizing the Lazy FP state restore technique for floating point state when context switching between application processes. A local attacker can conduct cache side-channel attacks and determine register values of other processes.
Note: This vulnerability is known as LazyFP.
MitigationUpdate the affected software.
Vulnerable software versionsIntel Core M 32nm: All versions
Intel Core M 45nm: All versions
Intel Core i7 32nm: All versions
Intel Core i7 45nm: All versions
Intel Core i5 32nm: All versions
Intel Core i5 45nm: All versions
Intel Core i3 32nm: All versions
Intel Core i3 45nm: All versions
CPE2.3 External linkshttp://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00145.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?