[VU:631579] Hardware debug exception documentation may result in unexpected behavior

Severity High
CVEs 1

Overview

In some circumstances, some operating systems or hypervisors may not expect or properly handle an Intel architecture hardware debug exception. The error appears to be due to developer interpretation of existing documentation for certain Intel architecture interrupt/exception instructions, namely MOV SS and POP SS.

Impact

An authenticated attacker may be able to read sensitive data in memory or control low-level operating system functions,

Solution

Apply an update Check with your operating system or software vendor for updates to address this issue. There is no expected performance impact for applying an update. A list of affected vendors and currently-known updates is provided below.

Acknowledgements

Microsoft and Intel credit Nick Peterson of Everdox Tech,LLC,for responsibly reporting this vulnerability and working with the group on coordinated disclosure. Andy Lutomirski is also credited for assistance in documenting the vulnerability for Linux.

ID
VU:631579
Severity
high
Severity from
CVE-2018-8897
URL
https://kb.cert.org/vuls/id/631579
Published
2018-05-08T17:19:58
(6 years ago)
Modified
2019-07-11T16:31:35
(5 years ago)
Rights
Copyright 2018, CERT Coordination Center (CERT/CC)
Other Advisories
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...