← Vulnerability feed

Vulnerability record · CVE-2017-5753 · published 4 January 2018

CVE-2017-5753: Intel CPUs speculative execution side-channel information disclosure (Spectre v1)

Intel · Atom C

CVE-2017-5753 is a speculative execution and branch prediction side-channel flaw in Intel microprocessors that can leak information through observable timing discrepancies. It is the variant commonly known as Spectre v1 and affects a broad range of Intel CPU families listed in the record. Because the leak is a side channel rather than a memory corruption bug, it is hard to detect and can expose sensitive data held in process memory.

5.6 CVSS 3.1 Medium EPSS 94% · top 0.2% CWE-203 · Observable discrepancy
5.6CVSS 3.1 base score, v2 4.7
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
132References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is a well-known, widely exploited class of CPU side channel with public proof-of-concept code and very high EPSS, though it requires local access and is not in KEV.

What it is

CVE-2017-5753 is a speculative execution and branch prediction side-channel flaw in Intel microprocessors that can leak information through observable timing discrepancies. It is the variant commonly known as Spectre v1 and affects a broad range of Intel CPU families listed in the record. Because the leak is a side channel rather than a memory corruption bug, it is hard to detect and can expose sensitive data held in process memory.

Impact

An attacker with local user access can read information they are not authorized to access by measuring side-channel timing differences. The CVSS vector rates confidentiality impact as High with no integrity or availability impact.

Attack surface

The vector is local (AV:L), requires low privileges (PR:L), and needs no user interaction (UI:N). The attack is reached by running code on the same system as the target data, not over the network.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.93838, 99.839th percentile) and references include an Exploit-tagged proof-of-concept. Public exploit code and extensive research exist, so exploitation is practical for a local attacker.

What to do

  • Apply CPU microcode and operating system, hypervisor, and browser updates that include Spectre v1 mitigations.
  • Enable compiler-based mitigations such as index masking, lfence insertion, or retpoline where supported by the toolchain.
  • Reduce local attack surface by limiting untrusted code execution and restricting interactive or low-privilege access on sensitive hosts.
  • For virtualized and cloud environments, ensure host and guest patches are applied and consider disabling same-host untrusted co-tenancy where feasible.
  • Track vendor advisories (Intel, Red Hat, Oracle, Xen, AWS, Mozilla, NVIDIA, Aruba, Siemens) for product-specific fixes.

Detection

  • Monitor for execution of known Spectre proof-of-concept binaries or unusual high-resolution timing code on sensitive hosts.
  • Watch for unexpected local privilege use or processes attempting to read memory outside their expected scope.
  • Use host-based telemetry to flag anomalous cache-timing or side-channel probing behavior where such sensors exist.
  • Verify patch and microcode levels across endpoints, servers, and hypervisors to confirm mitigations are actually in place.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html Mailing ListThird Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 Third Party Advisory
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html ExploitThird Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt Third Party Advisory
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt Third Party Advisory
http://www.kb.cert.org/vuls/id/584653 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchThird Party Advisory
http://www.securityfocus.com/bid/102371 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040071 Third Party AdvisoryVDB Entry
http://xenbits.xen.org/xsa/advisory-254.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0292 Third Party Advisory
https://access.redhat.com/security/vulnerabilities/speculativeexecution Third Party Advisory
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ Third Party Advisory
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ Third Party Advisory
https://cdrdv2.intel.com/v1/dl/getContent/685359 Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-002 Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2018-003 Third Party Advisory
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability Third Party Advisory
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2018/07/msg00020.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html Mailing ListThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 PatchThird Party AdvisoryVendor Advisory
https://seclists.org/bugtraq/2019/Jun/36 Issue TrackingMailing ListThird Party Advisory
https://security.gentoo.org/glsa/201810-06 Third Party Advisory
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html Third Party Advisory
https://security.netapp.com/advisory/ntap-20180104-0001/ Third Party Advisory
https://spectreattack.com/ Technical DescriptionThird Party Advisory

Track CVE-2017-5753 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-24489Intel atom x5-e3930 vulnerabilityIncomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.EPSS 0.35%7.8CVE-2020-0559Intel ac 3165 firmware incorrect permission assignment vulnerabilityInsecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat…EPSS 0.29%7.6CVE-2018-3652Intel xeon e3 information exposure vulnerabilityExisting UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…EPSS 0.37%6.8CVE-2021-33150Intel atom c2308 vulnerabilityHardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potenti…EPSS 0.35%6.5CVE-2022-0002Intel atom c3308 vulnerabilityNon-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable informati…EPSS 0.45%6.0CVE-2017-5703Intel core i7-8550u improper privilege management vulnerabilityConfiguration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially l…EPSS 0.34%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-3640Intel atom c observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2017-5753), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.