vendor:
Processors
by:
Google Project Zero
5.6
CVSS
MEDIUM
Spectre Attack
20
CWE
Product Name: Processors
Affected Version From: Intel, AMD, and ARM processors
Affected Version To: Intel, AMD, and ARM processors
Patch Exists: YES
Related CWE: CVE-2017-5753, CVE-2017-5715
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cesa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0496/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4021/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4012/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5753-workstation/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5753-fusion/, https://www.rapid7.com/db/vulnerabilities/cisco-xe-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/apple-safari-cve-2017-5753/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2017-5753/, https://www.rapid7.com/db/?q=CVE-2017-5753&type=&page=2, https://www.rapid7.com/db/?q=CVE-2017-5753&type=&page=2, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp10-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2021-26401/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cesa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0496/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4021/, https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3531-2/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4019/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4018/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4012/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0094/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0093/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4011/, https://www.rapid7.com/db/?q=CVE-2017-5715&type=&page=2, https://www.rapid7.com/db/?q=CVE-2017-5715&type=&page=3, https://www.rapid7.com/db/?q=CVE-2017-5715&type=&page=2
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
Spectre Attack
Spectre is a vulnerability that affects modern microprocessors that perform branch prediction. It allows an attacker to potentially read all memory, including memory allocated to the kernel and other programs. The attack works on Intel, AMD, and ARM processors. It was discovered by Google Project Zero and was publicly disclosed on January 3, 2018.
Mitigation:
Software updates and patches are available from vendors to mitigate the Spectre attack. Additionally, microcode updates from Intel and AMD are available to mitigate the attack.