Vulnerability record · CVE-2018-3639 · published 22 May 2018
CVE-2018-3639: Intel microprocessors speculative store bypass side-channel info disclosure
Intel · Atom C
CVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative execution. A local attacker can observe timing differences to infer data that should not be readable, leaking information across privilege boundaries. It matters because the affected product list is broad and the flaw is a hardware design issue requiring microcode and OS-level fixes.
Description
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityCVSS is medium (5.5) and exploitation requires local access, but the affected Intel product range is broad and EPSS is high.
What it is
CVE-2018-3639 is the Speculative Store Bypass (SSB) side-channel flaw, also called Variant 4, affecting Intel microprocessors that use speculative execution. A local attacker can observe timing differences to infer data that should not be readable, leaking information across privilege boundaries. It matters because the affected product list is broad and the flaw is a hardware design issue requiring microcode and OS-level fixes.
Impact
An attacker with local user access can disclose information from memory they are not authorized to read, via side-channel analysis. The CVSS vector shows confidentiality impact only, with no integrity or availability effect.
Attack surface
Reached locally on the affected system; the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs local user access but no user interaction. No network vector is described.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.60631 (99.1st percentile), indicating elevated likelihood of exploitation activity. Reference tags are advisory and mailing-list entries, with no exploit tag present.
What to do
- Apply Intel microcode updates and the corresponding operating system, hypervisor and firmware patches for Speculative Store Bypass.
- Enable the SSB mitigation controls provided by the OS or hypervisor where available.
- Restrict local interactive access and limit untrusted code execution on affected hosts.
- Track vendor advisories from Red Hat, Lenovo, Fujitsu and Xen for the specific affected platforms.
- Retire or isolate systems that cannot receive microcode or OS mitigations.
Detection
- Monitor for local exploitation tooling or proof-of-concept code targeting speculative execution side channels.
- Audit hosts for missing microcode or kernel patches associated with Speculative Store Bypass.
- Review local user access and process execution on systems with sensitive data and affected CPUs.
- Correlate unusual local timing or cache-probing behavior with suspicious process activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-3639 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3639), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.