← Vulnerability feed

Vulnerability record · CVE-2017-5754 · published 4 January 2018

CVE-2017-5754: Intel CPUs speculative execution side-channel information disclosure

Intel · Atom C

Intel microprocessors using speculative execution and indirect branch prediction can leak data through a side-channel analysis of the data cache. A local attacker with user access can read memory that should be inaccessible, which matters because it breaks process and kernel isolation on affected systems.

5.6 CVSS 3.1 Medium EPSS 84% · top 0.3% CWE-200 · Information exposure
5.6CVSS 3.1 base score, v2 4.7
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
132References
17 Jun 2026Last modified by NVD

Description

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw breaks memory isolation on a wide range of Intel CPUs and has a very high EPSS score, though it requires local access and high-complexity exploitation.

What it is

Intel microprocessors using speculative execution and indirect branch prediction can leak data through a side-channel analysis of the data cache. A local attacker with user access can read memory that should be inaccessible, which matters because it breaks process and kernel isolation on affected systems.

Impact

An attacker with local user access can disclose sensitive information from memory, potentially including kernel data or other processes' secrets. The scope change in the CVSS vector indicates the impact can cross a security boundary.

Attack surface

Reached locally by running code on the target system; no user interaction is required, but the attacker needs local user privileges. The CVSS vector is AV:L/AC:H/PR:L/UI:N, so exploitation requires local access and is rated high complexity.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.84172 (99.681st percentile), indicating a high likelihood of exploitation activity. Reference tags are mostly Third Party Advisory and do not confirm in-the-wild exploitation.

What to do

  • Apply vendor microcode, firmware, and OS kernel updates that implement mitigations for speculative execution side channels.
  • Enable available kernel page-table isolation or equivalent mitigations in the operating system.
  • Restrict local interactive access and limit untrusted code execution on affected hosts.
  • Follow Intel and OS vendor guidance for the specific affected processor families listed.
  • Monitor vendor advisories for updated mitigations and reapply as new guidance is released.

Detection

  • Monitor for unusual local processes performing high-volume cache-timing or memory-access patterns.
  • Audit and alert on unexpected local user accounts or code execution on systems with affected Intel CPUs.
  • Track patch and microcode levels on affected hosts and flag systems missing speculative-execution mitigations.
  • Correlate local privilege use with known side-channel proof-of-concept behavior where telemetry allows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 Third Party Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/4611
http://nvidia.custhelp.com/app/answers/detail/a_id/4613
http://nvidia.custhelp.com/app/answers/detail/a_id/4614
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
http://www.kb.cert.org/vuls/id/584653 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/102378
http://www.securityfocus.com/bid/106128
http://www.securitytracker.com/id/1040071 Third Party AdvisoryVDB Entry
http://xenbits.xen.org/xsa/advisory-254.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0292
https://access.redhat.com/security/vulnerabilities/speculativeexecution Third Party Advisory
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ Third Party Advisory
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ Third Party Advisory
https://cdrdv2.intel.com/v1/dl/getContent/685358
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
https://cert.vde.com/en-us/advisories/vde-2018-002
https://cert.vde.com/en-us/advisories/vde-2018-003
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Third Party Advisory
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
https://lists.debian.org/debian-lts-announce/2018/01/msg00004.html
https://meltdownattack.com/ Technical DescriptionThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 PatchThird Party AdvisoryVendor Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc
https://security.gentoo.org/glsa/201810-06
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html Third Party Advisory
https://security.netapp.com/advisory/ntap-20180104-0001/
https://source.android.com/security/bulletin/2018-04-01
https://support.citrix.com/article/CTX231399
https://support.citrix.com/article/CTX234679
https://support.f5.com/csp/article/K91229003 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us

Track CVE-2017-5754 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2018-3652Intel xeon e3 information exposure vulnerabilityExisting UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable p…EPSS 0.37%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-3640Intel atom c observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure…EPSS 7.6%5.6CVE-2018-9056Intel atom c information exposure vulnerabilitySystems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v…EPSS 0.67%5.6CVE-2017-5715Intel CPUs speculative execution side-channel information disclosureCVE-2017-5715 is the Spectre variant 2 flaw in Intel microprocessors that use speculative execution and indirect branch prediction. A local attacker …EPSS 74%analysed5.6CVE-2017-5753Intel CPUs speculative execution side-channel information disclosure (Spectre v1)CVE-2017-5753 is a speculative execution and branch prediction side-channel flaw in Intel microprocessors that can leak information through observabl…EPSS 94%analysed5.5CVE-2019-14615Canonical ubuntu linux vulnerabilityInsufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user …EPSS 1.4%5.5CVE-2018-3639Intel microprocessors speculative store bypass side-channel info disclosureCVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative ex…EPSS 61%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5754), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.